Vulnerability Name: Team Section Block <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Social Network Link CVE ID: CVE-2026-0833 CVSS Score: 6.4 (Medium) CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N Publicly Published Date: January 16, 2026 Last Updated Date: January 17, 2026 Researcher: Athiwat Tiprasaharn (Jitlada) Description: The Team Section Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping on user-supplied social network link URLs. Affected Version: <= 2.0.0 Patched Version: 2.0.1 Remediation: Update to version 2.0.1, or a newer patched version.