PT-2025-6546 · WordPress · Team Members Showcase Plugin
Abrahack
·
Published
2025-02-15
·
Updated
2025-02-24
·
CVE-2024-13439
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Team – Team Members Showcase Plugin plugin for WordPress versions up to, and including, 4.4.9
Description
The issue is related to unauthorized access due to a missing capability check on the
response() function. This allows authenticated attackers with Subscriber-level access and above to update the plugin's settings.Recommendations
For versions up to, and including, 4.4.9, consider disabling the
response() function until a patch is available to prevent unauthorized access.
As a temporary workaround, restrict access to the plugin's settings to minimize the risk of exploitation.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Team Members Showcase Plugin