plugin

Team Vulnerabilities

14 known security issues reported for the Team WordPress plugin. Most recent disclosed May 25, 2026.

4 high 3 medium

Running Team on your site? Check whether your installed version is affected.

Scan your site free

Team Showcase <= 1.22.28 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.22.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...

CVSS:
6.4
Affected:
up to 1.22.28
Fix:
No patched version reported
Disclosed:
May 25, 2026

CVE-2025-62745 on NVD →

Team Showcase [team] < 1.22.26

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Reflected XSS.This issue affects Team Showcase: from n/a through 1.22.25.

Affected:
up to 1.22.26
Fixed in:
1.22.26
Disclosed:
Sep 17, 2024

CVE-2024-44002 on NVD →

Team Showcase <= 1.22.25 - Reflected Cross-Site Scripting

medium

The Team Showcase plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.22.25 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully...

CVSS:
6.1
Affected:
up to 1.22.25
Fixed in:
1.22.26
Disclosed:
Sep 16, 2024

CVE-2024-44002 on NVD →

Team Showcase [team] < 1.22.24

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Stored XSS.This issue affects Team Showcase: from n/a through 1.22.23.

Affected:
up to 1.22.24
Fixed in:
1.22.24
Disclosed:
Aug 18, 2024

CVE-2024-43321 on NVD →

Team Showcase <= 1.22.23 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.22.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...

CVSS:
6.4
Affected:
up to 1.22.23
Fixed in:
1.22.24
Disclosed:
Aug 16, 2024

CVE-2024-43321 on NVD →

Team Showcase [team] < 1.22.16

unknown

[en] PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_i...

Affected:
up to 1.22.16
Fixed in:
1.22.16
Disclosed:
Jan 1, 2021

CVE-2020-35939 on NVD →

Team Showcase [team] < 1.22.16

unknown

[en] Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_import_xml_layouts.

Affected:
up to 1.22.16
Fixed in:
1.22.16
Disclosed:
Jan 1, 2021

CVE-2020-35937 on NVD →

Team Showcase [team] < 1.22.16

unknown

[en] Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import_xml_layouts.

Affected:
up to 1.22.16
Fixed in:
1.22.16
Disclosed:
Jan 1, 2021

CVE-2020-35936 on NVD →

Team Showcase [team] < 1.22.16

unknown

PHP Object Injection vulnerability found by Ramuel Gall (Wordfence) in WordPress Team Showcase plugin (versions <= 1.22.15).

Affected:
up to 1.22.16
Fixed in:
1.22.16
Disclosed:
Oct 5, 2020

Team Showcase [team] < 1.22.16

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Ramuel Gall (Wordfence) in WordPress Team Showcase plugin (versions <= 1.22.15).

Affected:
up to 1.22.16
Fixed in:
1.22.16
Disclosed:
Oct 5, 2020

Team Showcase <= 1.22.15 - Object Injection

high

PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import...

CVSS:
7.5
Affected:
up to 1.22.16
Fixed in:
1.22.16
Disclosed:
Sep 17, 2020

CVE-2020-35938 on NVD →

Team Showcase <= 1.22.15 - Stored Cross-Site Scripting

high

Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_import_xml_layouts.

CVSS:
7.5
Affected:
up to 1.22.16
Fixed in:
1.22.16
Disclosed:
Sep 17, 2020

CVE-2020-35937 on NVD →

Team Showcase <= 1.22.15 - Stored Cross-Site Scripting

high

Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import_xml_layouts.

CVSS:
7.5
Affected:
up to 1.22.16
Fixed in:
1.22.16
Disclosed:
Sep 17, 2020

CVE-2020-35936 on NVD →

Team Showcase <= 1.22.15 - Object Injection

high

PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_import...

CVSS:
7.5
Affected:
up to 1.22.16
Fixed in:
1.22.16
Disclosed:
Sep 17, 2020

CVE-2020-35939 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database