Description
WordPress Plugin Cherry Team Members is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Cherry Team Members version 1.4.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.4.2 or latest
References
Related Vulnerabilities
Vanilla Forums Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-1000432)
WordPress Plugin Dynamic Featured Image Unspecified Vulnerability (1.0.3)
osCommerce Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2002-1991)
Jboss EAP Improper Input Validation Vulnerability (CVE-2011-4314)