# Team Manager <= 2.6.7 - Unauthenticated Sensitive Information Exposure via Password-Protected Team Members

- **ID:** WPSEC-2026-0534
- **Plugin:** Dynamic Team Manager – Team Member Showcase with grid, slider, table  Elementor widget & shortcode (`wp-team-manager`), https://wordpress.org/plugins/wp-team-manager/
- **Affected versions:** all versions before 2.6.8
- **Fixed in:** 2.6.8 (Update to 2.6.8 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-200
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wp-team-manager
- **Fix released:** 2026-10-05
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0534/

## Description

The Team Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.7. The single team member template outputs member fields without checking whether the member is password-protected, and the team listings rendered by the plugin's shortcodes, block and Elementor widget do not exclude password-protected members. This makes it possible for unauthenticated attackers to read the details of password-protected team members, such as job titles, biographies, email addresses, phone numbers and social profile links, without knowing the password.

## References

- https://wpsec.com/vuln/WPSEC-2026-0534/
- https://plugins.svn.wordpress.org/wp-team-manager/tags/2.6.8/
- https://wordpress.org/plugins/wp-team-manager/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0534/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
