CVE-2024-9236: Team Members Showcase < 4.4.2 - Editor+ Stored XSS
The Team WordPress plugin before 4.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9236?
CVE-2024-9236 is considered a high severity vulnerability due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-9236?
To fix CVE-2024-9236, update the Team WordPress plugin to version 4.4.2 or higher.
Who is affected by CVE-2024-9236?
CVE-2024-9236 affects users of the Team WordPress plugin prior to version 4.4.2, particularly those with high privilege roles like admins.
What type of attack is enabled by CVE-2024-9236?
CVE-2024-9236 enables Stored Cross-Site Scripting attacks due to inadequate sanitization and escaping of settings.
Can multisite setups be affected by CVE-2024-9236?
Yes, multisite setups are affected by CVE-2024-9236 even when the unfiltered_html capability is disallowed.