CVE-2024-13362
Team Members – A WordPress Team Plugin with Gallery, Grid, Carousel, Slider, Table, List, and More
Minimum safe version
2.6.1
Update to 2.6.1 or later to address 9 fixable vulnerabilities
Freemius SDK <= 2.4.2 - Missing Authorization Checks
GS Team Members < 2.2.4 - Contributor+ Stored XSS
WordPress WordPress Team Members – GS Plugins Plugin <= 2.2.3 is vulnerable to Cross Site Scripting (XSS)
GS Team Members <= 2.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
WordPress WordPress Team Members – GS Plugins Plugin <= 2.2.1 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress WordPress Team Members – GS Plugins plugin <= 1.10.18 - Sensitive Information Disclosure vulnerability
WordPress WordPress Team Members – GS Plugins plugin <= 1.10.18 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability