CVE-2026-95592: WordPress Team plugin <= 6.0.0 - Insecure Direct Object References (IDOR) vulnerability
Published Sep 23, 2026
·Updated
Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions.
Affected Software
1 affected component
WordPress Team<=6.0.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Team pluginto a version that resolves this vulnerability.Fixed in 6.0.1
Event History
Sep 23, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or prior access to the site.
2
What is the likely impact of successful exploitation?
The available severity vector indicates low confidentiality impact, with no integrity or availability impact. This suggests unauthorized access to exposed information rather than modification or disruption.
3
Which plugin versions are affected?
Team plugin versions through 6.0.0 are affected, including version 6.0.0.