VendorsweDevswp_project_managerall versions
Vulnerabilities

weDevs WP Project Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2023-34383
WordPress WP Project Manager Plugin <= 2.6.0 is vulnerable to SQL Injection
Published 2023-11-03 · Modified
9.8EPSS 0.007
CVE-2023-40003
WordPress WP Project Manager plugin <= 2.6.7 - Broken Access Control vulnerability
Published 2024-12-13 · Modified
9.8EPSS 0.005
CVE-2023-3636
WP Project Manager <= 2.6.4 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation
Published 2023-08-31 · Modified
8.8EPSS 0.009
CVE-2020-36745
WP Project Manager <= 2.4.0 - Cross-Site Request Forgery Bypass
Published 2023-07-01 · Modified
8.8EPSS 0.004
CVE-2025-32280
WordPress WP Project Manager plugin < 2.6.25 - Cross Site Request Forgery (CSRF) Vulnerability
Published 2025-04-04 · Modified
8.8EPSS 0.002
CVE-2024-10174
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.13 - Insecure Direct Object Reference to Unauthenticated Authorization Bypass
Published 2024-11-13 · Analyzed
7.3EPSS 0.007
CVE-2024-13752
WP Project Manager <= 2.6.17 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update
Published 2025-02-15 · Analyzed
6.5EPSS 0.005
CVE-2024-12195
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.16 - Authenticated (Subscriber+) SQL Injection
Published 2025-01-04 · Analyzed
6.5EPSS 0.004
CVE-2024-13500
WP Project Manager <= 2.6.17 - Authenticated (Subscriber+) SQL Injection via orderby Parameter
Published 2025-02-15 · Analyzed
6.5EPSS 0.004
CVE-2024-10548
WP Project Manager <= 2.6.15 - Authenticated (Subscriber+) Sensitive Information Exposure via Project Task List REST API
Published 2024-12-19 · Analyzed
6.5EPSS 0.004
CVE-2023-49860
WordPress WP Project Manager Plugin <= 2.6.7 is vulnerable to Cross Site Scripting (XSS)
Published 2023-12-14 · Modified
6.5EPSS 0.004
CVE-2025-2541
WP Project Manager <= 2.6.22 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
Published 2025-04-11 · Analyzed
6.4EPSS 0.003
CVE-2025-3100
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.22 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload
Published 2025-04-09 · Analyzed
6.4EPSS 0.003
CVE-2025-22649
WordPress WP Project Manager plugin <= 2.6.22 - Cross Site Scripting (XSS) vulnerability
Published 2025-03-27 · Modified
5.9EPSS 0.003
CVE-2021-36826
WordPress WP Project Manager plugin <= 2.4.13 - Stored Cross-Site Scripting (XSS) vulnerability
Published 2022-04-04 · Modified
5.4EPSS 0.006
CVE-2024-10520
WP Project Manager <= 2.6.14 - Missing Authorization to Project Milestone and Task Creation/Deletion
Published 2024-11-20 · Analyzed
5.3EPSS 0.003