Sceawere
Vulnerability Detail
CVE-2026-102402UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in Team Members Showcase
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 3h ago
- Vendor
- techlabpro1
- Product
- Team – Team Members Showcase Plugin
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ttp_filter_taxonomy (meta of the attacker-chosen post)' parameter in all versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-10-10T07:16:39.980Z",
"pubdate": "2026-10-10T07:16:39.980Z",
"executiveSummary": "The Team Members Showcase plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 6.0.2.\nThe vulnerability originates from inadequate input sanitization and output escaping mechanisms applied to the 'ttp_filter_taxonomy' parameter, which processes metadata associated with user-defined posts.\nAuthenticated attackers with contributor-level privileges or higher can weaponize this flaw to inject malicious JavaScript payloads into the application.\nWhen a victim, such as an administrator or end-user, interacts with a page containing the injected content, the script executes within the context of the victim's browser session.\nSuccessful exploitation poses significant security risks, including unauthorized access to session cookies, sensitive information theft, or potential account takeover.\nBecause the payload is stored persistently in the database, the malicious script remains active until manually removed, enabling a broad attack surface against any user viewing the compromised pages.",
"technicalDetails": "The root cause of this vulnerability is the failure of the 'Team – Team Members Showcase' plugin to properly sanitize user-supplied input during the processing of taxonomy metadata via the 'ttp_filter_taxonomy' parameter. By neglecting to apply robust input validation or context-aware output encoding, the plugin inadvertently allows the injection of arbitrary HTML and JavaScript tags into the WordPress database.\nExploitation is feasible for any authenticated user holding contributor-level access or higher. The attack flow involves an attacker manipulating the 'ttp_filter_taxonomy' meta-data associated with a post within the plugin's framework. During the update or creation process of a team member profile, the attacker injects a malicious payload—typically consisting of standard <script> tags or event handlers—into the metadata field. Because the backend application processes this meta value without stripping or neutralizing executable code, the malicious payload is committed directly to the WordPress 'wp_postmeta' (or equivalent) database table.\nThe vulnerability manifests during the rendering stage when the plugin retrieves the stored metadata for display on the front-end. The component responsible for rendering these team member posts fails to implement appropriate output escaping (such as escaping entities or using WordPress sanitization functions like esc_js or esc_html). Consequently, the web browser interprets the stored malicious string as executable code rather than plain text.\nWhen an unsuspecting victim visits a page where the infected team member post is rendered, the browser triggers the injected script. This execution occurs within the security context of the origin site, granting the script access to the victim's Document Object Model (DOM), browser storage, and authenticated session tokens. Post-exploitation impact is severe, potentially allowing an attacker to perform actions on behalf of the victim, redirect users to malicious domains, or exfiltrate sensitive data, such as CSRF nonces or administrative session identifiers, thereby facilitating privilege escalation or full site compromise."
}