Impact
The WP Responsive Meet The Team plugin for WordPress is vulnerable to stored cross‑site scripting through its wprm_team shortcode. Because the plugin fails to sanitize input or escape output from user‑supplied attributes, an attacker can embed arbitrary JavaScript code into the page content. When a visitor loads a page containing the compromised shortcode, the injected script runs in the visitor’s browser, allowing the attacker to steal credentials, hijack sessions, or perform other malicious actions within the victim’s browser context.
Affected Systems
Any site running the vobi WP Responsive Meet The Team plugin with a version equal to or older than 1.0.1 is affected. Users should verify the plugin version and discontinue use of versions up to 1.0.1 or seek a patch when available.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Authenticated users with contributor or higher privileges can exploit the flaw by inserting malicious attributes into the shortcode; the attack surface is therefore limited to sites where contributors are able to add or edit content using this plugin.
OpenCVE Enrichment