CVE-2026-11871 PUBLISHED

Team Showcase Supreme <= 9.2 - Unauthenticated Sensitive Data Disclosure via wpm_6310_team_member_details

Assigner: WPScan
Reserved: 10.06.2026 Published: 26.09.2026 Updated: 26.09.2026

The Team Members WordPress plugin through 9.2 does not perform any authorization or visibility check in an unauthenticated AJAX action that returns full team member records by ID, allowing unauthenticated attackers to enumerate and disclose details, including email addresses and phone numbers, of team members the administrator has not published publicly.

Product Status

Vendor Unknown
Product Team Members
Versions Default: unknown
  • affected from 0 to 9.2 (incl.)

Credits

  • Vaibhav Narkhede finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE