The Team WordPress plugin before 4.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
History

Thu, 12 Jun 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Radiustheme
Radiustheme team - Wordpress Team Members Showcase
Weaknesses CWE-79
CPEs cpe:2.3:a:radiustheme:team_-_wordpress_team_members_showcase:*:*:*:*:*:wordpress:*:*
Vendors & Products Radiustheme
Radiustheme team - Wordpress Team Members Showcase

Sat, 17 May 2025 04:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 20:15:00 +0000

Type Values Removed Values Added
Description The Team WordPress plugin before 4.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Title Team Members Showcase < 4.4.2 - Editor+ Stored XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-05-15T20:07:20.348Z

Updated: 2025-05-17T02:57:37.151Z

Reserved: 2024-09-26T18:52:43.164Z

Link: CVE-2024-9236

cve-icon Vulnrichment

Updated: 2025-05-17T02:57:31.853Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-15T20:16:00.390

Modified: 2025-06-12T16:43:19.150

Link: CVE-2024-9236

cve-icon Redhat

No data.