The Team Members – Multi Language Supported Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Metrics
Affected Vendors & Products
References
History
Tue, 30 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 30 Jun 2026 03:00:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-06-30T15:59:00.959Z
Reserved: 2026-06-12T14:44:10.569Z
Link: CVE-2026-12114
Updated: 2026-06-30T14:20:49.029Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-30T04:30:04Z