{
 "id": "WPSEC-2026-0534",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0534/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0534/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0534/index.md",
 "title": "Team Manager <= 2.6.7 - Unauthenticated Sensitive Information Exposure via Password-Protected Team Members",
 "description": "The Team Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.7. The single team member template outputs member fields without checking whether the member is password-protected, and the team listings rendered by the plugin's shortcodes, block and Elementor widget do not exclude password-protected members. This makes it possible for unauthenticated attackers to read the details of password-protected team members, such as job titles, biographies, email addresses, phone numbers and social profile links, without knowing the password.",
 "plugin": {
  "slug": "wp-team-manager",
  "name": "Team Manager",
  "full_name": "Dynamic Team Manager – Team Member Showcase with grid, slider, table  Elementor widget & shortcode",
  "wordpress_org": "https://wordpress.org/plugins/wp-team-manager/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wp-team-manager/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wp-team-manager"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-200"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "2.6.8",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 2.6.8"
  ]
 },
 "introduced_in": null,
 "fixed_in": "2.6.8",
 "remediation": "Update to 2.6.8 or later.",
 "fix_released": "2026-10-05T06:28:15+00:00",
 "published": "2026-10-07T12:46:23+00:00",
 "updated": "2026-10-07T12:34:55.330824+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0534/",
  "https://plugins.svn.wordpress.org/wp-team-manager/tags/2.6.8/",
  "https://wordpress.org/plugins/wp-team-manager/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wp-team-manager",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}