
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13403 is a Missing Authorization vulnerability in the Employee Spotlight – Team Member Showcase & Meet the Team WordPress plugin that allows authenticated attackers to modify tracking settings without proper authorization. All versions up to and including 5.1.3 are affected. The flaw was published on December 13, 2025, and assigned by Wordfence. It carries a CVSS v3.1 base score of 4.3 (Medium) (Red Hat CVE, Wordfence).
The root cause is a missing authorization check (CWE-862) in the employee_spotlight_check_optin() function within includes/plugin-feedback-functions.php. Because no capability or nonce validation is enforced before executing the function, any authenticated user — including those with only Subscriber-level access — can send a crafted network request to toggle the plugin's tracking opt-in/opt-out settings. The vulnerable code path is visible in the plugin's public Subversion repository at line 19 of the affected file (Wordfence, WordPress Trac).
Exploitation allows a low-privileged authenticated attacker to arbitrarily enable or disable the plugin's tracking/telemetry settings, resulting in a limited integrity impact with no confidentiality or availability consequences. While the direct impact is confined to the plugin's tracking configuration, unauthorized modification of opt-in settings could affect data collection behavior or obscure plugin usage analytics. The vulnerability scope is unchanged, meaning it does not provide a path to broader system compromise or lateral movement (Red Hat CVE, Wordfence).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.028%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum a valid Subscriber-level WordPress account, limiting the attack surface compared to unauthenticated vulnerabilities (Wordfence, Red Hat CVE).
employee_spotlight_check_optin() — typically registered via WordPress hooks and callable by any authenticated user.wp-admin/admin-ajax.php (or equivalent) with the appropriate action parameter targeting employee_spotlight_check_optin and the desired opt-in state value.wp-admin/admin-ajax.php with an action parameter related to employee_spotlight_check_optin from Subscriber-level user accounts.employee_spotlight_optin or similar option key) at unusual times or from unexpected user accounts.Update the Employee Spotlight plugin to version 5.1.4 or later, which introduces proper authorization validation on the employee_spotlight_check_optin() function. The fix is available via the WordPress Plugin Repository and can be applied through the standard WordPress admin update mechanism. The patch changeset is publicly available in the plugin's SVN repository (WordPress Trac). As a temporary workaround, site administrators can deactivate the plugin until the update is applied, or restrict Subscriber-level user registration if not required (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."