5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Description
The Employee Spotlight – Team Member Showcase & Meet the Team Plugin for WordPress is vulnerable to unauthorized tracking settings modification due to missing authorization validation on the employee_spotlight_check_optin() function in all versions up to, and including, 5.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable or disable tracking settings.
Basic Information
ID
CVE-2025-13403
Source
Wordfence
Published
Dec 13, 2025 at 03:20
Affected Product
Vendor
emarket-design
Product
Employee Spotlight – Team Member Showcase & Meet the Team Plugin
Version
*
Affected Versions
emarket-design Employee Spotlight – Team Member Showcase & Meet the Team Plugin *
CWE Classification
References
- www.wordfence.com /threat-intel/vulnerabilities/id/19738a82-8c31-45bb-a869-68e357299eb5
- plugins.trac.wordpress.org /browser/employee-spotlight/trunk/includes/plugin-feedback-functions.php
- plugins.trac.wordpress.org /browser/employee-spotlight/tags/5.1.3/includes/plugin-feedback-functions.php
- plugins.trac.wordpress.org /changeset