plugin

Tlp Team Vulnerabilities

12 known security issues reported for the Tlp Team WordPress plugin. Most recent disclosed Mar 23, 2026.

2 high 5 medium

Running Tlp Team on your site? Check whether your installed version is affected.

Scan your site free

Team – Team Members Showcase Plugin <= 5.0.11 - Missing Authorization

medium

The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.0.11. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 5.0.11
Fixed in:
5.0.12
Disclosed:
Mar 23, 2026

CVE-2026-25026 on NVD →

Team &#8211; Team Members Showcase Plugin [tlp-team] <= 5.0.13 (unfixed)

unknown

[en] Missing Authorization vulnerability in RadiusTheme Team tlp-team allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team: from n/a through <= 5.0.13.

Affected:
up to 5.0.13
Fix:
No patched version reported
Disclosed:
Mar 13, 2026

CVE-2026-32396 on NVD →

Team <= 5.0.13 - Missing Authorization

medium

The Team plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.0.13. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 5.0.13
Fixed in:
5.0.14
Disclosed:
Feb 20, 2026

CVE-2026-32396 on NVD →

Team &#8211; Team Members Showcase Plugin [tlp-team] < 5.0.11

unknown

[en] The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

Affected:
up to 5.0.11
Fixed in:
5.0.11
Disclosed:
Jan 5, 2026

CVE-2025-14124 on NVD →

Team <= 5.0.10 - Unauthenticated SQL Injection

high

The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 5.0.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to appe...

CVSS:
7.5
Affected:
up to 5.0.10
Fixed in:
5.0.11
Disclosed:
Dec 15, 2025

CVE-2025-14124 on NVD →

Team <= 5.0.6 - Missing Authorization

medium

The Team plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.0.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
5.4
Affected:
up to 5.0.6
Fixed in:
5.0.7
Disclosed:
Sep 22, 2025

CVE-2025-57975 on NVD →

Team &#8211; Team Members Showcase Plugin [tlp-team] < 5.0.0

unknown

[en] The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the response() function in all versions up to, and including, 4.4.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugi...

Affected:
up to 5.0.0
Fixed in:
5.0.0
Disclosed:
Feb 15, 2025

CVE-2024-13439 on NVD →

Team – Team Members Showcase Plugin <= 4.4.9 - Missing Authorization to Authenticated (Subscriber+) Settings Update

medium

The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the response() function in all versions up to, and including, 4.4.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's s...

CVSS:
4.3
Affected:
up to 4.4.9
Fixed in:
5.0.0
Disclosed:
Feb 14, 2025

CVE-2024-13439 on NVD →

Team – Team Members Showcase Plugin <= 4.4.1 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions an...

CVSS:
4.4
Affected:
up to 4.4.1
Fixed in:
4.4.2
Disclosed:
Oct 3, 2024

CVE-2024-9236 on NVD →

Team &#8211; Team Members Showcase Plugin [tlp-team] < 4.1.2

unknown

[en] The Team WordPress plugin before 4.1.2 contains a file which could allow any authenticated users to download arbitrary files from the server via a path traversal vector. Furthermore, the file will also be deleted after its content is returned to the user

Affected:
up to 4.1.2
Fixed in:
4.1.2
Disclosed:
Aug 22, 2022

CVE-2022-2557 on NVD →

Team - WordPress Team Member Showcase Plugin <= 4.1.1 - Directory Traversal to Arbitrary File Read/Deletion

high

The Team - WordPress Team Member Showcase Plugin for WordPress is vulnerable to directory traversal via the 'resources/download.php' file. This allows authenticated attackers to download a copy of any file on the server, and then delete the original from the server, granted the 'wp-content/plugins/tlp-team/temp' folder...

CVSS:
7.5
Affected:
up to 4.1.1
Fixed in:
4.1.2
Disclosed:
Jul 29, 2022

CVE-2022-2557 on NVD →

Team &#8211; Team Members Showcase Plugin [tlp-team] < 4.4.2

unknown
Affected:
up to 4.4.2
Fixed in:
4.4.2

CVE-2024-9236 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database