s2Member v260814 (Framework and Pro) was released on August 14th, 2026.
Unified Changelog for s2Member & s2Member Pro v260814
v260814
-
(Framework) Improvement: Better s2Member Security Encryption Key handling and related guidance in the admin panel.
-
(Framework) Improvement: Hardened input validation and sanitization for the
s2Key,s2File,s2Stream, ands2Member-PayPal-Buttonshortcodes. -
(Framework & Pro) Improvement: Renamed and expanded the
s2Getshortcode’s user-field whitelist into the shared Shortcode User Fields Whitelist setting, now used fors2Get‘suser_idattribute ands2Member-List‘sshow_fieldsattribute. Administrators are warned when either shortcode attempts to display an un-whitelisted field’s value that doesn’t belong to the current user viewing the page. -
(Framework & Pro) Security: Improved validation and hardened handling of serialized data throughout s2Member.
-
(Pro) Improvement: Hardened input validation and sanitization for the
s2Member-Login,s2Member-Summary,s2Member-Gift-Codes,s2Member-List,s2Member-List-Search-Box, ands2Member-Pro-ClickBank-Buttonshortcodes, as well as the Pro Login Widget. -
(Pro) Security: Added stricter handling for
s2Member-List‘sshow_fieldsattribute. s2Member will warn administrators about detected fields that still need review. Fields not whitelisted will not be displayed. Sites usingshow_fieldsshould review General Options > Shortcode User Fields Whitelist and allow the fields their Member Lists are intended to display. -
(Pro) Security: Added safer handling and a whitelist for the
templateshortcode attribute, used by thes2Member-List,s2Member-List-Search-Box, and Stripe, PayPal, and Authorize.Net Pro-Forms shortcodes. s2Member will warn administrators about detected templates that still need review. Templates not whitelisted will not be used, and the standard template will be used instead. Sites using custom templates should review General Options > Pro Shortcode Templates Whitelist and allow their custom template files. -
(Pro) Fix: Prevented the Pro updater from offering or installing a Pro release newer than the installed s2Member Framework, avoiding compatibility issues until the Framework is updated first.
-
(Pro) Fix: Prevented Stripe payment processing from continuing after Pro-Form validation rejects a submission, avoiding misleading Stripe card-field errors when other required form fields are missing.
-
(Pro) Fix: Updated Stripe Pro-Forms to use the shortcode’s
validate_zipcodeattribute correctly, so it can override the default setting to collect and validate the card’s postal code.