plugin

Team Members Vulnerabilities

11 known security issues reported for the Team Members WordPress plugin. Most recent disclosed Sep 26, 2025.

5 medium

Running Team Members on your site? Check whether your installed version is affected.

Scan your site free

Team Members <= 5.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Team Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the first and last name fields in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to in...

CVSS:
6.4
Affected:
up to 5.3.5
Fixed in:
5.3.6
Disclosed:
Sep 26, 2025

CVE-2025-8440 on NVD →

Team Members [team-members] < 5.3.4

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Members allows Stored XSS.This issue affects Team Members: from n/a through 5.3.3.

Affected:
up to 5.3.4
Fixed in:
5.3.4
Disclosed:
Jul 20, 2024

CVE-2024-38670 on NVD →

Team Members <= 5.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Team Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages tha...

CVSS:
6.4
Affected:
up to 5.3.3
Fixed in:
5.3.4
Disclosed:
Jul 10, 2024

CVE-2024-38670 on NVD →

Team Members [team-members] < 5.3.2

unknown

[en] The Team Members WordPress plugin before 5.3.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the author role and above to perform Stored Cross-Site Scripting attacks.

Affected:
up to 5.3.2
Fixed in:
5.3.2
Disclosed:
Mar 18, 2024

CVE-2024-1331 on NVD →

Team Members <= 5.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Team Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 5.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level...

CVSS:
6.4
Affected:
up to 5.3.1
Fixed in:
5.3.2
Disclosed:
Feb 26, 2024

CVE-2024-1331 on NVD →

Team Members [team-members] < 5.2.1

unknown

[en] The Team Members WordPress plugin before 5.2.1 does not sanitize and escapes some of its settings, which could allow high-privilege users such as editors to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in a multisite setup).

Affected:
up to 5.2.1
Fixed in:
5.2.1
Disclosed:
Jan 2, 2023

CVE-2022-3936 on NVD →

Team Members <= 5.2.0 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Team Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters in versions up to, and including, 5.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to injec...

CVSS:
5.5
Affected:
up to 5.2.0
Fixed in:
5.2.1
Disclosed:
Dec 9, 2022

CVE-2022-3936 on NVD →

Team Members [team-members] < 5.1.1

unknown

[en] The Team Members WordPress plugin before 5.1.1 does not escape some of its Team settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

Affected:
up to 5.1.1
Fixed in:
5.1.1
Disclosed:
May 30, 2022

CVE-2022-1568 on NVD →

Team Members <= 5.1.0 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Team Members WordPress plugin before 5.1.1 does not escape some of its Team settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVSS:
5.5
Affected:
up to 5.1.0
Fixed in:
5.1.1
Disclosed:
May 9, 2022

CVE-2022-1568 on NVD →

Team Members [team-members] < 5.0.4

unknown

[en] Unvalidated input and lack of output encoding in the Team Members WordPress plugin, versions before 5.0.4, lead to Cross-site scripting vulnerabilities allowing medium-privileged authenticated attacker (contributor+) to inject arbitrary web script or HTML via the 'Description/biography' of a member.

Affected:
up to 5.0.4
Fixed in:
5.0.4
Disclosed:
Mar 18, 2021

CVE-2021-24128 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database