Sceawere

Vulnerability Detail

CVE-2026-102402UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS in Team Members Showcase

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
3h ago
Vendor
techlabpro1
Product
Team – Team Members Showcase Plugin
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ttp_filter_taxonomy (meta of the attacker-chosen post)' parameter in all versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-10-10T07:16:39.980Z",
  "pubdate": "2026-10-10T07:16:39.980Z",
  "executiveSummary": "The Team Members Showcase plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 6.0.2.\nThe vulnerability originates from inadequate input sanitization and output escaping mechanisms applied to the 'ttp_filter_taxonomy' parameter, which processes metadata associated with user-defined posts.\nAuthenticated attackers with contributor-level privileges or higher can weaponize this flaw to inject malicious JavaScript payloads into the application.\nWhen a victim, such as an administrator or end-user, interacts with a page containing the injected content, the script executes within the context of the victim's browser session.\nSuccessful exploitation poses significant security risks, including unauthorized access to session cookies, sensitive information theft, or potential account takeover.\nBecause the payload is stored persistently in the database, the malicious script remains active until manually removed, enabling a broad attack surface against any user viewing the compromised pages.",
  "technicalDetails": "The root cause of this vulnerability is the failure of the 'Team – Team Members Showcase' plugin to properly sanitize user-supplied input during the processing of taxonomy metadata via the 'ttp_filter_taxonomy' parameter. By neglecting to apply robust input validation or context-aware output encoding, the plugin inadvertently allows the injection of arbitrary HTML and JavaScript tags into the WordPress database.\nExploitation is feasible for any authenticated user holding contributor-level access or higher. The attack flow involves an attacker manipulating the 'ttp_filter_taxonomy' meta-data associated with a post within the plugin's framework. During the update or creation process of a team member profile, the attacker injects a malicious payload—typically consisting of standard <script> tags or event handlers—into the metadata field. Because the backend application processes this meta value without stripping or neutralizing executable code, the malicious payload is committed directly to the WordPress 'wp_postmeta' (or equivalent) database table.\nThe vulnerability manifests during the rendering stage when the plugin retrieves the stored metadata for display on the front-end. The component responsible for rendering these team member posts fails to implement appropriate output escaping (such as escaping entities or using WordPress sanitization functions like esc_js or esc_html). Consequently, the web browser interprets the stored malicious string as executable code rather than plain text.\nWhen an unsuspecting victim visits a page where the infected team member post is rendered, the browser triggers the injected script. This execution occurs within the security context of the origin site, granting the script access to the victim's Document Object Model (DOM), browser storage, and authenticated session tokens. Post-exploitation impact is severe, potentially allowing an attacker to perform actions on behalf of the victim, redirect users to malicious domains, or exfiltrate sensitive data, such as CSRF nonces or administrative session identifiers, thereby facilitating privilege escalation or full site compromise."
}
CVE-2026-102402: Stored XSS in Team Members Showcase (MEDIUM Severity, CVSS: 6.4) | Sceawere