Junglewise Threat Intelligence

CVE-2026-12114: wpmart Team Members Plugin Stored XSS in admin settings

CVE-2026-12114 · Severity: medium · CVSS 4.4 · Published 2026-06-30

Executive brief

The Team Members plugin for WordPress, which is used to display staff profiles on websites, contains a security flaw in its administrative settings. This vulnerability allows high-level users (administrators) to save malicious scripts that will run in the browsers of other users who visit the site. This issue primarily impacts WordPress multi-site networks or specific configurations where standard security restrictions on HTML content have been relaxed.

Technical details

The Team Members – Multi Language Supported Team Plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the admin settings component. An authenticated attacker with administrator-level permissions can inject arbitrary web scripts into the database. These scripts then execute in the context of a user's browser whenever they access the affected page. This vulnerability specifically impacts WordPress multi-site installations or environments where the 'unfiltered_html' capability has been disabled for administrators. The issue is present in all versions up to and including 8.7.

Affected products

  • wpmart Team Members – Multi Language Supported Team Plugin up to, and including, 8.7

Timeline

  • 2026-06-30: disclosed: NVD publication date

References