Hi, it seems like the current version has not resolved this issue. For more information on this critical security issue: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/team-showcase-supreme/team-member-71-authenticated-editor-local-file-inclusion
Team Member <= 7.3 – Authenticated (Editor+) Local File Inclusion
Wordfence Intelligence???>???Vulnerability Database???>???Team Member <= 7.3 – Authenticated (Editor+)
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’)
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVECVE-2024-52385
CVSS7.2 (High)Publicly PublishedNovember 11, 2024
Last UpdatedNovember 27, 2024
ResearcherJo?o Pedro Soares de Alcantara – Kinorth
Description
The Team Member plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.3. This makes it possible for authenticated attackers, with editor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
References
Multi Language Supported Team Plugin?Team Member – Multi Language Supported Team Plugin
Software Type PluginSoftware Slugteam-showcase-supreme?(view on www.remarpro.com)
Patched??No
Remediation No known patch available.
Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement.
Affected Version