CVE-2026-11871
Received Received - Intake

Unauthenticated Information Disclosure in Team Members WordPress Plugin

Vulnerability report for CVE-2026-11871, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-26

Last updated on: 2026-09-26

Assigner: WPScan

Description

The Team Members WordPress plugin through 9.2 does not perform any authorization or visibility check in an unauthenticated AJAX action that returns full team member records by ID, allowing unauthenticated attackers to enumerate and disclose details, including email addresses and phone numbers, of team members the administrator has not published publicly.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-26
Last Modified
2026-09-26
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
team_members wordpress_plugin to 9.2 (inc)
team_showcase_supreme plugin to 9.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Team Members WordPress plugin (versions 9.2 and below). It allows unauthenticated attackers to access sensitive team member details like email addresses and phone numbers through an AJAX action that lacks proper authorization checks. The flaw enables enumeration of unpublished team member records.

Detection Guidance

To detect this vulnerability, check if the Team Members or Team Showcase Supreme WordPress plugins are installed and their versions. Look for unauthenticated AJAX requests to endpoints that return team member records by ID. Use tools like curl to test if sensitive data is exposed by querying IDs directly.

Impact Analysis

Attackers could exploit this to steal personal data of team members, including contact information not meant for public view. This could lead to privacy breaches, phishing attacks, or identity theft targeting team members or their contacts.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized access to personal data. GDPR requires protection of personal data, while HIPAA mandates safeguards for protected health information. Unauthorized disclosure risks legal penalties and reputational damage.

Mitigation Strategies

Immediately disable the Team Members or Team Showcase Supreme plugins if installed. Monitor network traffic for unauthorized AJAX requests to team member endpoints. Consider implementing web application firewalls to block suspicious requests until a patch is released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11871. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart