« Volver al listado

Wedevs

Wedevs WP Project Manager: vulnerabilidades y CVE

Wedevs WP Project Manager tiene 21 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE21
Últimos 12 meses4
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-97281Media (6.3)——1 oct 2026
Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions.
CVE-2026-78262Crítica (9.8)0.56%—24 ago 2026
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
CVE-2025-68040Media (6.5)0.26%—29 dic 2025
Insertion of Sensitive Information Into Sent Data vulnerability in weDevs WP Project Manager wedevs-project-manager allows Retrieve Embedded Sensitive Data.This issue affects WP Project Manager: from n/a through <=…
CVE-2025-8994Media (6.5)0.28%—15 nov 2025
The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘completed_at_operator’ parameter…
CVE-2025-58269Media (5.3)0.29%—22 sept 2025
Use of Hard-coded Credentials vulnerability in weDevs WP Project Manager wedevs-project-manager allows Retrieve Embedded Sensitive Data.This issue affects WP Project Manager: from n/a through <= 2.6.25.
CVE-2025-2541Media (5.4)0.31%—11 abr 2025
The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22 due to insufficient input sanitization and output escaping. This…
CVE-2025-3100Media (5.4)0.28%—9 abr 2025
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to,…
CVE-2025-32280Alta (8.8)0.17%—4 abr 2025
Cross-Site Request Forgery (CSRF) vulnerability in weDevs WP Project Manager wedevs-project-manager allows Cross Site Request Forgery.This issue affects WP Project Manager: from n/a through < 2.6.25.
CVE-2025-22649Media (4.8)0.27%—27 mar 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project Manager wedevs-project-manager allows Stored XSS.This issue affects WP Project Manager: from n/a…
CVE-2024-13500Media (6.5)0.43%—15 feb 2025
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up…
CVE-2024-13752Media (6.5)0.52%—15 feb 2025
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check in the…
CVE-2024-12195Media (6.5)0.43%—4 ene 2025
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to SQL Injection via the 'project_id' parameter of the…
CVE-2024-10548Media (6.5)0.40%—19 dic 2024
The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.15 via the Project Task List ('/wp-json/pm/v2/projects/1/task-lists') REST API…
CVE-2023-40003Crítica (9.8)0.50%—13 dic 2024
Missing Authorization vulnerability in weDevs WP Project Manager wedevs-project-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Project Manager: from n/a through <=…
CVE-2024-10520Media (5.3)0.32%—20 nov 2024
The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' method of the 'Create_Milestone', 'Create_Task_List', 'Create_Task', and…
CVE-2024-10174Alta (7.3)0.66%—13 nov 2024
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including,…
CVE-2023-49860Media (5.4)0.39%—14 dic 2023
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts allows…
CVE-2023-34383Crítica (9.8)0.68%—3 nov 2023
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP Project Manager wedevs-project-manager allows SQL Injection.This issue affects WP Project Manager: from n/a…
CVE-2023-3636Alta (8.8)0.86%—31 ago 2023
The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.4 due to insufficient restriction on the 'save_users_map_name' function. This makes it possible for…
CVE-2020-36745Alta (8.8)0.44%—1 jul 2023
The WP Project Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.0. This is due to missing or incorrect nonce validation on the do_updates() function. This…
CVE-2021-36826Media (5.4)0.62%—4 abr 2022
Authenticated (subscriber or higher user role if allowed to access projects) Stored Cross-Site Scripting (XSS) vulnerability in weDevs WP Project Manager plugin <= 2.4.13 versions.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter1
  2. T1078 Valid Accounts1
  3. T1190 Exploit Public-Facing Application1
  4. T1210 Exploitation of Remote Services1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Wedevs