Stored Cross-Site Scripting in Team Master Plugin for WordPress
CVE-2026-8870
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 May 2026
What is CVE-2026-8870?
The Team Master plugin for WordPress allows authenticated users with contributor-level access and above to exploit a stored cross-site scripting vulnerability through insufficient input sanitization and output escaping of shortcode attributes. This flaw enables attackers to inject arbitrary web scripts into web pages, which will execute whenever a user accesses the compromised page, potentially leading to data theft or further exploitation of the site.
Affected Version(s)
Team Master β A Modern WordPress Team Showcase 0 <= 1.1.2