Team Members Showcase Plugin Missing Authorization Vulnerability in WordPress

Vulnerability

A vulnerability exists in the Team – Team Members Showcase Plugin for WordPress, in all versions through 4.4.9. The issue arises from a lack of proper capability checks in the response() function, allowing authenticated attackers with Subscriber-level access or higher to unauthorizedly modify the plugin's settings.

Impact

Exploitation of this vulnerability allows for unauthorized users with Subscriber-level access and above to update the plugin's settings, potentially leading to unauthorized changes in how team members are displayed or managed.

Reproduction

To reproduce this vulnerability, an authenticated user with Subscriber-level access or higher can send an AJAX request to the 'tlpTeamSettings' endpoint. The request must include a valid nonce to bypass the security check. Once the request is processed, the user can update the plugin's settings without proper authorization.

Remediation

Users are advised to update the Team Members Showcase Plugin to version 5.0.0 or later, where this vulnerability has been patched.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.3
remediation
7.7
relevance
0.0
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.