Vulnerability in Team – Team Members Showcase Plugin — CVE-2026-102402
MediumSeverity
—Estimated exploit probability
10,000+ sitesInstalls
6.0.3Fixed in
What to do now
Update Team – Team Members Showcase Plugin to 6.0.3 or later.
Affected versions
- Everything up to and including 6.0.2
Affected: Team – Team Members Showcase Plugin (plugin, tlp-team)
What the vulnerability is
The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ttp_filter_taxonomy (meta of the attacker-chosen post)' parameter in all versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.