Description
The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ttp_filter_taxonomy (meta of the attacker-chosen post)' parameter in all versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-10-10
Score: 6.4 Medium
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting via the 'ttp_filter_taxonomy' meta field used by the [tlpteam] shortcode
Action: Apply Patch
AI Analysis

Impact

The Team – Team Members Showcase Plugin is vulnerable to stored cross‑site scripting (XSS) because it fails to properly sanitize and escape the 'ttp_filter_taxonomy' metadata that can be set by an attacker. An authenticated contributor or higher user can inject arbitrary JavaScript into the page content, which will execute every time any user views a page containing the malicious entry. The impact is the compromise of confidentiality, integrity, and availability of user sessions and data, allowing an attacker to hijack accounts, deface sites, or steal credentials.

Affected Systems

This flaw exists in all releases of the Team – Team Members Showcase Plugin through version 6.0.2, which is distributed by TechLabPro1. Users of any WordPress installation running this plugin with the [tlpteam] shortcode enabled and whose accounts have contributor or higher privileges are potentially affected.

Risk and Exploitability

The CVSS score of 6.4 indicates a medium severity vulnerability. The EPSS score is not available, but because the flaw requires only an authenticated contributor–level account, the likelihood of exploitation in a realistic environment is moderate; it is not listed in the CISA KEV catalog. Attackers could exploit the vulnerability by creating or modifying posts that include the vulnerable meta and then encouraging other users to access those posts, leading to the execution of embedded scripts. The impact can be widespread if the site serves many users.

Generated by OpenCVE AI on October 10, 2026 at 08:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Team – Team Members Showcase Plugin to a version released after 6.0.2 that fixes the XSS issue.
  • If an update is not currently available, deactivate the [tlpteam] shortcode or remove posts that contain the 'ttp_filter_taxonomy' meta to eliminate stored malicious payloads.
  • Implement a web application firewall or XSS filtering rules to block execution of injected scripts until the plugin is patched.

Generated by OpenCVE AI on October 10, 2026 at 08:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ttp_filter_taxonomy (meta of the attacker-chosen post)' parameter in all versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Team <= 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'ttp_filter_taxonomy' Post Meta via [tlpteam] Shortcode
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T06:40:14.291Z

Reserved: 2026-09-29T00:16:28.245Z

Link: CVE-2026-102402

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T07:16:39.980

Modified: 2026-10-10T07:16:39.980

Link: CVE-2026-102402

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T08:30:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')