Vulnerabilities / Team Manager / WPSEC-2026-0535

Team Manager <= 2.6.7 - Authenticated (Contributor+) Insecure Direct Object Reference to Sensitive Information Exposure via dwl_create_team Shortcode

Medium 4.3 CWE-639Fixed in 2.6.8
ID
WPSEC-2026-0535
Plugin
Dynamic Team Manager – Team Member Showcase with grid, slider, table Elementor widget & shortcode (wp-team-manager)
Affected
from 2.2.9 before 2.6.8
Remediation
Update to 2.6.8 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-639
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
Attack surface
Team Manager on WPSec AttackSurface
Fix released
Published

Description

The Team Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 2.2.9 up to, and including, 2.6.7 via the 'id' attribute of the dwl_create_team shortcode, due to missing validation that the referenced post is a published Team Generator. The shortcode reads all post meta of the referenced post and outputs it in the page's data-settings attribute. This makes it possible for authenticated attackers with contributor-level access and above to read the post meta of arbitrary posts, including private posts, other users' drafts and other post types, along with protected meta fields stored by other plugins.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0