CVE-2024-12563
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Mar 18, 2025
CWE ID 98
Summary
CVE-2024-12563 is a vulnerability affecting the s2Member Pro plugin for WordPress. This issue, present in all versions up to 250214, enables authenticated attackers with contributor-level permissions or higher to execute arbitrary files on the server through the 'template' attribute in a Local File Inclusion vulnerability. An attacker can exploit this vulnerability to bypass access controls, obtain sensitive data, and execute PHP code within those files, potentially leading to serious security implications.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.