Team Members <= 5.0.3 - Authenticated Cross-Site Scripting
mediumUnvalidated input and lack of output encoding in the Team Members WordPress plugin, versions before 5.0.4, lead to Cross-site scripting vulnerabilities allowing medium-privileged authenticated attacker (contributor+) to inject arbitrary web script or HTML via the 'Description/biography' of a member.
- CVSS:
- 6.4
- Affected:
- up to 5.0.4
- Fixed in:
- 5.0.4
- Disclosed:
- May 16, 2020