WordPress Plugin Vulnerabilities

Team Members < 5.0.4 - Authenticated Stored Cross-Site Scripting (XSS)

Description

Cross-site scripting vulnerabilities in Team Members version 5.0.3 and lower allow medium-privileged authenticated attacker (contributor+) to inject arbitrary web script or HTML via the 'Description/biography' of a member.

Proof of Concept

Affects Plugins

Fixed in 5.0.4

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
minhtuanact
Submitter
SunCSR (Sun Cyber Security Research)
Verified
No

Timeline

Publicly Published
2020-05-16 (about 5 years ago)
Added
2020-05-16 (about 5 years ago)
Last Updated
2021-01-21 (about 4 years ago)

Other