# Team Manager <= 2.6.7 - Authenticated (Contributor+) Insecure Direct Object Reference to Sensitive Information Exposure via dwl_create_team Shortcode

- **ID:** WPSEC-2026-0535
- **Plugin:** Dynamic Team Manager – Team Member Showcase with grid, slider, table  Elementor widget & shortcode (`wp-team-manager`), https://wordpress.org/plugins/wp-team-manager/
- **Affected versions:** from 2.2.9 before 2.6.8
- **Fixed in:** 2.6.8 (Update to 2.6.8 or later.)
- **Severity:** Medium 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-639
- **Usage among sites WPSec scans:** plugin Low, affected versions None seen (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wp-team-manager
- **Fix released:** 2026-10-05
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0535/

## Description

The Team Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 2.2.9 up to, and including, 2.6.7 via the 'id' attribute of the dwl_create_team shortcode, due to missing validation that the referenced post is a published Team Generator. The shortcode reads all post meta of the referenced post and outputs it in the page's data-settings attribute. This makes it possible for authenticated attackers with contributor-level access and above to read the post meta of arbitrary posts, including private posts, other users' drafts and other post types, along with protected meta fields stored by other plugins.

## References

- https://wpsec.com/vuln/WPSEC-2026-0535/
- https://plugins.svn.wordpress.org/wp-team-manager/tags/2.6.8/
- https://wordpress.org/plugins/wp-team-manager/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0535/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
