Junglewise Threat Intelligence

CVE-2026-11871: Team Showcase Supreme information disclosure via AJAX

CVE-2026-11871 · Severity: info · Published 2026-09-26

Executive brief

The Team Showcase Supreme WordPress plugin fails to verify user permissions when processing team member lookup requests, allowing anyone on the internet to retrieve sensitive employee information including email addresses and phone numbers that administrators have not published. This enables attackers to build a directory of company staff without authorization.

Technical details

The plugin's wpm_6310_team_member_details AJAX action does not perform authentication or authorization checks, permitting unauthenticated attackers to query team member records by ID. By iterating through IDs, an attacker can enumerate all team members and extract full details, including unpublished contact information. The vulnerability is a classic information disclosure flaw due to missing access controls on an API endpoint.

Affected products

  • Team Showcase Supreme Team Showcase Supreme through 9.2

Timeline

  • 2026-09-23: disclosed
  • 2026-09-26: advisory

References