Impact
The Team – Team Members Showcase Plugin is vulnerable to stored cross‑site scripting (XSS) because it fails to properly sanitize and escape the 'ttp_filter_taxonomy' metadata that can be set by an attacker. An authenticated contributor or higher user can inject arbitrary JavaScript into the page content, which will execute every time any user views a page containing the malicious entry. The impact is the compromise of confidentiality, integrity, and availability of user sessions and data, allowing an attacker to hijack accounts, deface sites, or steal credentials.
Affected Systems
This flaw exists in all releases of the Team – Team Members Showcase Plugin through version 6.0.2, which is distributed by TechLabPro1. Users of any WordPress installation running this plugin with the [tlpteam] shortcode enabled and whose accounts have contributor or higher privileges are potentially affected.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium severity vulnerability. The EPSS score is not available, but because the flaw requires only an authenticated contributor–level account, the likelihood of exploitation in a realistic environment is moderate; it is not listed in the CISA KEV catalog. Attackers could exploit the vulnerability by creating or modifying posts that include the vulnerable meta and then encouraging other users to access those posts, leading to the execution of embedded scripts. The impact can be widespread if the site serves many users.
OpenCVE Enrichment