CVE-2011-5082

UnknownEPSS 1.96%

Last modified

CVE-2011-5082 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code field).. EPSS estimates a 1.96% chance of exploitation in the next 30 days.

Description

Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code field).

Metrics

EPSS Probability
1.96%

77.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
S2memberS2member<= 111216
S2memberS2member110604
S2memberS2member110605
S2memberS2member110606
S2memberS2member110617
S2memberS2member110620
S2memberS2member110708
S2memberS2member110709
S2memberS2member110710
S2memberS2member110731
S2memberS2member110812
S2memberS2member110815
S2memberS2member110912
S2memberS2member110913
S2memberS2member110915
S2memberS2member110926
S2memberS2member110927
S2memberS2member111002
S2memberS2member111003
S2memberS2member111011
S2memberS2member111017
S2memberS2member111029
S2memberS2member111105
S2memberS2member111206

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2011-5082?
Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code field).
How severe is CVE-2011-5082?
Severity scoring for CVE-2011-5082 is pending analysis. The EPSS model estimates a 1.96% probability of exploitation in the next 30 days.
How do I fix CVE-2011-5082?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2011-5082?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST