Team Manager <= 2.6.7 - Authenticated (Contributor+) Insecure Direct Object Reference to Sensitive Information Exposure via dwl_create_team Shortcode
- ID
- WPSEC-2026-0535
- Plugin
- Dynamic Team Manager – Team Member Showcase with grid, slider, table Elementor widget & shortcode (wp-team-manager)
- Affected
- from 2.2.9 before 2.6.8
- Remediation
- Update to 2.6.8 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-639
- Usage
- Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
- Attack surface
- Team Manager on WPSec AttackSurface
- Fix released
- Published
Description
The Team Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 2.2.9 up to, and including, 2.6.7 via the 'id' attribute of the dwl_create_team shortcode, due to missing validation that the referenced post is a published Team Generator. The shortcode reads all post meta of the referenced post and outputs it in the page's data-settings attribute. This makes it possible for authenticated attackers with contributor-level access and above to read the post meta of arbitrary posts, including private posts, other users' drafts and other post types, along with protected meta fields stored by other plugins.
References
- https://wpsec.com/vuln/WPSEC-2026-0535/
- https://plugins.svn.wordpress.org/wp-team-manager/tags/2.6.8/
- https://wordpress.org/plugins/wp-team-manager/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS