CVE-2024-1331
CVE-2024-1331: Stored Cross-Site Scripting (XSS) vulnerability in the Team Members WordPress plugin. This flaw, affecting versions prior to 5.3.2, arises from inadequate validation and escaping of shortcode attributes. Users with author privileges or higher can exploit this to inject malicious scripts into website pages or posts.
The injected scripts can execute when other users view the affected content, potentially leading to account compromise, data theft, or website defacement. While the CVSS score is 0, the SOCRadar Vulnerability Risk Score (SVRS) is 30, indicating a moderate level of risk. This score suggests that while not immediately critical, the vulnerability should be addressed to prevent potential exploitation. Addressing this vulnerability promptly is crucial to maintain the security and integrity of websites using the Team Members WordPress plugin.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.