Vulnerabilities / Team Manager / WPSEC-2026-0534

Team Manager <= 2.6.7 - Unauthenticated Sensitive Information Exposure via Password-Protected Team Members

Medium 5.3 CWE-200Fixed in 2.6.8
ID
WPSEC-2026-0534
Plugin
Dynamic Team Manager – Team Member Showcase with grid, slider, table Elementor widget & shortcode (wp-team-manager)
Affected
all versions before 2.6.8
Remediation
Update to 2.6.8 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-200
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
Team Manager on WPSec AttackSurface
Fix released
Published

Description

The Team Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.7. The single team member template outputs member fields without checking whether the member is password-protected, and the team listings rendered by the plugin's shortcodes, block and Elementor widget do not exclude password-protected members. This makes it possible for unauthenticated attackers to read the details of password-protected team members, such as job titles, biographies, email addresses, phone numbers and social profile links, without knowing the password.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0