Team Manager <= 2.6.7 - Unauthenticated Sensitive Information Exposure via Password-Protected Team Members
- ID
- WPSEC-2026-0534
- Plugin
- Dynamic Team Manager – Team Member Showcase with grid, slider, table Elementor widget & shortcode (wp-team-manager)
- Affected
- all versions before 2.6.8
- Remediation
- Update to 2.6.8 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-200
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- Team Manager on WPSec AttackSurface
- Fix released
- Published
Description
The Team Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.7. The single team member template outputs member fields without checking whether the member is password-protected, and the team listings rendered by the plugin's shortcodes, block and Elementor widget do not exclude password-protected members. This makes it possible for unauthenticated attackers to read the details of password-protected team members, such as job titles, biographies, email addresses, phone numbers and social profile links, without knowing the password.
References
- https://wpsec.com/vuln/WPSEC-2026-0534/
- https://plugins.svn.wordpress.org/wp-team-manager/tags/2.6.8/
- https://wordpress.org/plugins/wp-team-manager/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS