What the vulnerability does
01Description
Improper Privilege Management vulnerability in WP Sharks s2Member Pro allows Privilege Escalation.This issue affects s2Member Pro: from n/a through 240315.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Improper Privilege Management vulnerability in WP Sharks s2Member Pro allows Privilege Escalation.This issue affects s2Member Pro: from n/a through 240315.
Explanation of Vulnerability in Simple Terms
s2Member Pro versions up to 240315 contain a privilege management flaw that allows unauthenticated attackers to read sensitive data over the network. The vulnerability requires no user interaction and can be exploited remotely. Site administrators should update to a version newer than the affected range immediately.
What an attacker can do
Read sensitive information from the site without logging in.
Potential impact on your site
Confidential data may be exposed to anyone on the internet without needing a user account.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities