Team Member Showcase Staff List Plugin – Employee Spotlight, CVE-2025-13403
- CVE, Research URL
- Home page URL
-
Security reports for Team Member Showcase Staff List Plugin – Employee Spotlight
- Published on
- Dec 13, 2025
- Research Description
- The Employee Spotlight – Team Member Showcase & Meet the Team Plugin for WordPress is vulnerable to unauthorized tracking settings modification due to missing authorization validation on the employee_spotlight_check_optin() function in all versions up to, and including, 5.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable or disable tracking settings.
- Affected versions
-
max 5.1.4.
- Status
-
vulnerable