WPIntell

Source evidence

Critical Issue Found

Team Members – Multi Language Supported Team Plugin · support · 2024-11-25T18:59:00+00:00

mixedsentiment
highseverity
0.95relevance
5replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

4 / 26 rows with source links

15.4% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

22 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
Marianne Wolda resolved
I just ran a Wordfence scan on my site and this is what it found. Is there a patch for this?: The Plugin “Team Member – Multi Language Supported Team Plugin” has a security vulnerability. Type: Plugin Vulnerable Issue status: Critical Plugin Name: Team Member – Multi Language Supported Team Plugin Current Plugin Version: 7.1 Details: To protect your site from this vulnerability, the safest option is to deactivate and completely remove “Team Member – Multi Language Supported Team Plugin” until a patched version is available. Vulnerability Severity: 7.2/10.0 (High) The page I need help with: [ log in to see the link] Hi, We already fixed the issue. Please upgrade the plugin in the latest version. Hi, it seems like the current version has not resolved this issue. For more information on this critical security issue: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/team-showcase-supreme/team-member-71-authenticated-editor-local-file-inclusion Team Member <= 7.3 – Authenticated (Editor+) Local File Inclusion Wordfence Intelligence > Vulnerability Database > Team Member <= 7.3 – Authenticated (Editor+) Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) CVSS Vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVE CVE-2024-52385 CVSS7.2 (High)Publicly PublishedNovember 11, 2024 Last UpdatedNovember 27, 2024 Researcher João Pedro Soares de Alcântara – Kinorth Description The Team Member plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.3. This makes it possible for authenticated attackers, with editor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. References patchstack.com Multi Language Supported Team Plugin Team Member – Multi Language Supported Team Plugin Software Type PluginSoftware Slugteam-showcase-supreme (view on wordpress.org) Patched? No Remediation No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement. Affected Version <= 7.3 Yes, we already sent the team plugin to review on patchstack. Still waiting for their reply. For references, please check this URL. https://wpmart.org/wp-content/uploads/2024/11/Screenshot-2024-11-30-at-10.33.43 PM.png Thanks for your attention on this. Yes, I’m all updated and still getting the Critical notification: I’m still getting the same “critical” notification.

Comments

5 shown
wpmart 2024-11-26T03:06:00+00:00

Hi, We already fixed the issue. Please upgrade the plugin in the latest version.

migueldvasquez 2024-12-03T17:04:00+00:00

Hi, it seems like the current version has not resolved this issue. For more information on this critical security issue: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/team-showcase-supreme/team-member-71-authenticated-editor-local-file-inclusion Team Member <= 7.3 – Authenticated (Editor+) Local File Inclusion Wordfence Intelligence > Vulnerability Database > Team Member <= 7.3 – Authenticated (Editor+) Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) CVSS Vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVE CVE-2024-52385 CVSS7.2 (High)Publicly PublishedNovember 11, 2024 Last UpdatedNovember 27, 2024 Researcher João Pedro Soares de Alcântara – Kinorth Description The Team Member plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.3. This makes it possible for authenticated attackers, with editor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. References patchstack.com Multi Language Supported Team Plugin Team Member – Multi Language Supported Team Plugin Software Type PluginSoftware Slugteam-showcase-supreme (view on wordpress.org) Patched? No Remediation No known patch available. Please review the vulnerability’s details in depth and employ mitigations based on your organization’s risk tolerance. It may be best to uninstall the affected software and find a replacement. Affected Version <= 7.3

wpmart 2024-12-03T17:16:00+00:00

Yes, we already sent the team plugin to review on patchstack. Still waiting for their reply. For references, please check this URL. https://wpmart.org/wp-content/uploads/2024/11/Screenshot-2024-11-30-at-10.33.43 PM.png

Marianne Wolda 2024-12-06T15:12:00+00:00

Thanks for your attention on this. Yes, I’m all updated and still getting the Critical notification:

Marianne Wolda 2024-12-27T21:08:00+00:00

I’m still getting the same “critical” notification.