Impact
The Team Members – Best WordPress Team Plugin is vulnerable to stored cross‑site scripting through the social link icon fields in all versions up to 3.4.1. The vulnerability results from insufficient input sanitization and lack of output escaping, allowing an authenticated user with a Contributor role or higher to embed arbitrary scripts. Once executed, these scripts run in the browsers of any visitor to the page containing the injected content, potentially leading to session hijacking, defacement, or data exfiltration.
Affected Systems
The affected product is the wpspeedo Team Members Showcase plugin for WordPress, any installation using version 3.4.1 or earlier.
Risk and Exploitability
The vulnerability has a CVSS score of 6.4 and an EPSS score of less than 1 %, indicating moderate impact but low probability of exploitation. It is not listed in the CISA KEV catalog. The likely attack path requires the attacker to log in with Contributor or higher privileges, edit a social link icon entry, and then have an end user visit the modified page. Because the exploit requires authenticated access, the immediate risk to sites without Contributor accounts is lower, but once such accounts exist the risk increases.
OpenCVE Enrichment
EUVD