CVE-2011-5082

S2member < 111216 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code field).

Scores

EPSS 0.0025
EPSS Percentile 48.4%

Classification

CWE
CWE-79
Status published

Affected Products (25)

s2member/s2member < 111216
s2member/s2member
s2member/s2member
s2member/s2member
s2member/s2member
s2member/s2member
s2member/s2member
s2member/s2member
s2member/s2member
s2member/s2member
s2member/s2member
s2member/s2member
s2member/s2member
s2member/s2member
s2member/s2member
... and 10 more

Timeline

Published Mar 19, 2012
Tracked Since Feb 18, 2026