Access violation vulnerability in Team Builder – Meet the Team 1.3

The Team Builder – Meet the Team plugin for WordPress has a security issue that allows unauthorized changes to be made to its data. This is because there is no check in place to ensure that only authorized users can modify the save_team_builder_options() function, in all versions up to and including 1.3. As a result, attackers who have at least Subscriber-level access to the site can make changes to the plugin’s settings.

Detected in:

Team Builder – Meet the Team open vulnerable versions: >= * <= 1.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.