CRITICAL
WordPress s2Member plugin <= 250905 - Remote Code Execution (RCE) vulnerability
Published Oct 22, 2025
9.0
CRITICALCVSS 3.1
EPSS 0.42%
Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member.This issue affects s2Member: from n/a through 250905.
Affected products
-
Affected
- ≥ 0, ≤ 250905
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Cristián Lávaque | s2Member | unaffected | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update the WordPress s2Member plugin to the latest available version (at least 251005).
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-35385 Advisory
- https://patchstack.com/database/Wordpress/Plugin/s2member/vulnerability/wordpress-s2member-plugin-250905-remote-code-execution-rce-vulnerability?_s_id=cve vdb-entry
- https://patchstack.com/database/wordpress/plugin/s2member/vulnerability/wordpress-s2member-plugin-250905-remote-code-execution-rce-vulnerability?_s_id=cve vdb-entry
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Patchstack
Published Oct 22, 2025
Updated Sep 29, 2026
Reserved Oct 7, 2025
Link CVE-2025-62023
CISA Vulnrichment
Updated Apr 27, 2026
Red Hat
No data
GitHub
No data