📦 Wp Project Manager

by Wedevs

🔍 What is Wp Project Manager?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-10174

HIGH CVSS 7.3 Nov 13, 2024

The WP Project Manager plugin for WordPress has an Insecure Direct Object Reference vulnerability that allows unauthenticated attackers to impersonate administrators by manipulating the 'user_id' para...

CVE-2023-3636

HIGH CVSS 8.8 Aug 31, 2023

The WP Project Manager WordPress plugin up to version 2.6.4 contains a privilege escalation vulnerability. Authenticated attackers with minimal permissions (such as subscribers) can modify their user ...

CVE-2025-2541

MEDIUM CVSS 6.4 Apr 11, 2025

The WP Project Manager WordPress plugin has a stored XSS vulnerability in SVG file uploads affecting all versions up to 2.6.22. Authenticated attackers with Author-level access can inject malicious sc...

CVE-2025-32280

MEDIUM CVSS 4.3 Apr 4, 2025

A Cross-Site Request Forgery (CSRF) vulnerability in weDevs WP Project Manager allows attackers to trick authenticated administrators into performing unintended actions. This affects WordPress sites r...

CVE-2024-13500

MEDIUM CVSS 6.5 Feb 15, 2025

This vulnerability allows authenticated attackers with Subscriber-level access or higher to perform time-based SQL injection attacks via the 'orderby' parameter in the WP Project Manager plugin. Attac...

CVE-2024-10548

MEDIUM CVSS 6.5 Dec 19, 2024

The WP Project Manager WordPress plugin exposes hashed passwords and other sensitive data through an insecure REST API endpoint. Authenticated attackers with Subscriber-level access or higher can expl...