Custom Team Manager
Custom Team Manager has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Custom Team Manager has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Bao - BlueRock. Custom Team Manager is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.0.14.
CVE-2025-58840Custom Team Manager <= 2.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Custom Team Manager
Author
Ibnul H.
This plugin will display team members of your company using shortcode on your post or page. You just need to post members details same way as you add a new post. And everything will be there automatically. Use Team Management menu to add new member and see team-members page. It’s shortcode enabled, responsive and easy to use. You can change to Gridview display of members from Settings page. There are few other options too. Recommended Plugins Post Types Order – With Post Types Order, you can reorder your team members easily, it’s just drag and drop. Plugin Features You can add/edit member detail same way as post add/edit. Responsive layout. Shortcode enabled. Settings page with Ajax save. Members pagination with ajax loading. Excellent CSS3 modern effects. Easy to customize (if needed). Automatic members page creation. Option to specify number of team members to display. Custom CSS option. How To Use Install / Activate the plugin Add Team Members from Management Team menu on Dashboard. See Team Members page. Use Settings page to changes settings and custom CSS Use [cmt-content]your content here[/cmt-content] to show some content before or after shortcode [team-members] or [team-members-profile] – it’ll position the content correctly. If you use single profile on single page and get 404 Not Found for single full profile page, you need to flush permalink. Just go to Dashboard->Settings->Permalink , then click on Save button. You don’t need anything to change. THAT’S ALL ! ENJOY !
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C