{
 "id": "WPSEC-2026-0535",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0535/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0535/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0535/index.md",
 "title": "Team Manager <= 2.6.7 - Authenticated (Contributor+) Insecure Direct Object Reference to Sensitive Information Exposure via dwl_create_team Shortcode",
 "description": "The Team Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 2.2.9 up to, and including, 2.6.7 via the 'id' attribute of the dwl_create_team shortcode, due to missing validation that the referenced post is a published Team Generator. The shortcode reads all post meta of the referenced post and outputs it in the page's data-settings attribute. This makes it possible for authenticated attackers with contributor-level access and above to read the post meta of arbitrary posts, including private posts, other users' drafts and other post types, along with protected meta fields stored by other plugins.",
 "plugin": {
  "slug": "wp-team-manager",
  "name": "Team Manager",
  "full_name": "Dynamic Team Manager – Team Member Showcase with grid, slider, table  Elementor widget & shortcode",
  "wordpress_org": "https://wordpress.org/plugins/wp-team-manager/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wp-team-manager/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wp-team-manager"
 },
 "type": "IDOR",
 "cwe": [
  "CWE-639"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "2.2.9",
    "from_inclusive": true,
    "to": "2.6.8",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 2.2.9 before 2.6.8"
  ]
 },
 "introduced_in": "2.2.9",
 "fixed_in": "2.6.8",
 "remediation": "Update to 2.6.8 or later.",
 "fix_released": "2026-10-05T06:28:15+00:00",
 "published": "2026-10-07T12:46:23+00:00",
 "updated": "2026-10-07T12:34:55.330824+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0535/",
  "https://plugins.svn.wordpress.org/wp-team-manager/tags/2.6.8/",
  "https://wordpress.org/plugins/wp-team-manager/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wp-team-manager",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "None seen",
  "as_of": "2026-10-07"
 }
}