Impact
The Team Master plugin stores an arbitrary script that an authenticated contributor can embed via shortcode attributes. This stored XSS is rendered when anyone views the affected page, potentially allowing session hijacking, credential theft, or defacement. The flaw stems from insufficient input validation and output escaping (CWE‑79).
Affected Systems
WordPress installations running Team Master – A Modern WordPress Team Showcase up to and including version 1.1.2 are vulnerable. No specific sub‑versions are listed beyond this upper bound.
Risk and Exploitability
The CVSS score of 6.4 reflects moderate severity; EPSS is not available, and the vulnerability is not yet listed in CISA's KEV catalog. An attacker with contributor or higher access can directly inject and store malicious code that will execute in any victim’s browser who views the page. While no public exploits are documented, the attack is straightforward for anyone who can obtain a contributor role, underscoring the need for immediate remediation.
OpenCVE Enrichment