CVE-2023-5639: Team Showcase <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tmfshortcode' shortcode in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for the Team Showcase plugin?
The vulnerability ID for the Team Showcase plugin is CVE-2023-5639.
What is the severity of CVE-2023-5639?
The severity of CVE-2023-5639 is medium.
What is the affected software for CVE-2023-5639?
The affected software for CVE-2023-5639 is the Team Showcase plugin for WordPress version up to, and including, 2.1.
How does CVE-2023-5639 affect the Team Showcase plugin?
CVE-2023-5639 affects the Team Showcase plugin by allowing stored cross-site scripting via the plugin's 'tmfshortcode' shortcode due to insufficient input sanitization and output escaping on user supplied attributes.
Is there a fix for CVE-2023-5639?
Yes, there is a fix for CVE-2023-5639. It is recommended to update to the latest version of the Team Showcase plugin for WordPress.