Impact
Team Showcase plugin contains a missing authorization flaw that lets attackers exploit poorly configured access control levels. The vulnerability enables an actor to view or manipulate content that should be restricted by the site’s permission settings, potentially revealing private information or allowing unauthorized actions. The weakness stems from improper validation of user privileges, as classified by CWE-862.
Affected Systems
The vulnerability affects the WordPress Team Showcase plugin by cmoreira. All release versions older than 25.05.13 are susceptible, while any release 25.05.13 or newer contains a fix and is considered safe.
Risk and Exploitability
With a CVSS score of 4.3, the threat is low to moderate. The EPSS score of less than 1% indicates a very low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. The most probable attack vector is through the WordPress web interface, where a user with minimal privileges or even an unauthenticated visitor could access restricted areas if the plugin’s access checks are bypassed. No additional exploitation prerequisites are detailed in the available data.
OpenCVE Enrichment
EUVD