CVE-2011-5082
medium
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
4.3
Description
Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code field).
Predictions
Exploit likelihood
20%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| s2member | s2member | {"endIncluding":"111216"} | |
| s2member | s2member | 110604 | |
| s2member | s2member | 110605 | |
| s2member | s2member | 110606 | |
| s2member | s2member | 110617 | |
| s2member | s2member | 110620 | |
| s2member | s2member | 110708 | |
| s2member | s2member | 110709 | |
| s2member | s2member | 110710 | |
| s2member | s2member | 110731 | |
| s2member | s2member | 110812 | |
| s2member | s2member | 110815 | |
| s2member | s2member | 110912 | |
| s2member | s2member | 110913 | |
| s2member | s2member | 110915 | |
| s2member | s2member | 110926 | |
| s2member | s2member | 110927 | |
| s2member | s2member | 111002 | |
| s2member | s2member | 111003 | |
| s2member | s2member | 111011 | |
| s2member | s2member | 111017 | |
| s2member | s2member | 111029 | |
| s2member | s2member | 111105 | |
| s2member | s2member | 111206 | |
| wordpress | wordpress | | |
References
- http://secunia.com/advisories/47954
- http://www.primothemes.com/forums/viewtopic.php?f=4&t=16173#p56982
- http://www.securityfocus.com/bid/51997
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73202
- http://secunia.com/advisories/47954
- http://www.primothemes.com/forums/viewtopic.php?f=4&t=16173#p56982
- http://www.securityfocus.com/bid/51997
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73202
CWEs
CWE-79
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.