Skip to main content

Vendor/product archive

wedevs / wp_project_manager CVEs

Beta · best-effort

16 CVEs tagged to wedevs / wp_project_manager0 Critical, 3 High, 13 Medium, 0 Low, 0 Unrated.

CVE-2025-2541

Published Apr 11, 2025

The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22 due to insufficient inpu…

CVSS 6.4 · Medium
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2025-3100

Published Apr 9, 2025

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SV…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32280

Published Apr 4, 2025

Cross-Site Request Forgery (CSRF) vulnerability in weDevs WP Project Manager wedevs-project-manager allows Cross Site Request Forgery.This issue affects WP Project Manager: from n…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-22649

Published Mar 27, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project Manager wedevs-project-manager allows Stored XSS.This issue…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-13500

Published Feb 15, 2025

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13752

Published Feb 15, 2025

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to unauthorized loss of data due to a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12195

Published Jan 4, 2025

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to SQL Injection via the 'project_id'…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10548

Published Dec 19, 2024

The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.15 via the Project Task List ('/wp-json/pm/v2…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40003

Published Dec 13, 2024

Missing Authorization vulnerability in weDevs WP Project Manager wedevs-project-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-10520

Published Nov 20, 2024

The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' method of the 'Create_Milestone', '…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10174

Published Nov 13, 2024

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Insecure Direct Object Reference i…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49860

Published Dec 14, 2023

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project Manager – Task, team, and project management plugin featuri…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-34383

Published Nov 3, 2023

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP Project Manager wedevs-project-manager allows SQL Injection.This is…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-3636

Published Aug 31, 2023

The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.4 due to insufficient restriction on the 'save_users_map_na…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2020-36745

Published Jul 1, 2023

The WP Project Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.0. This is due to missing or incorrect nonce validati…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36826

Published Apr 4, 2022

Authenticated (subscriber or higher user role if allowed to access projects) Stored Cross-Site Scripting (XSS) vulnerability in weDevs WP Project Manager plugin <= 2.4.13 versions.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1