Wedevs
Wedevs WP Project Manager: vulnerabilities and CVEs
Wedevs WP Project Manager has 21 published vulnerabilities, 4 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.
CVEs21
Last 12 months4
Critical3
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-97281 | Medium (6.3) | 0.25% | — | Oct 1, 2026 | Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions. |
| CVE-2026-78262 | Critical (9.8) | 0.56% | — | Aug 24, 2026 | Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions. |
| CVE-2025-68040 | Medium (6.5) | 0.26% | — | Dec 29, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in weDevs WP Project Manager wedevs-project-manager allows Retrieve Embedded Sensitive Data.This issue affects WP Project Manager: from n/a through <=… |
| CVE-2025-8994 | Medium (6.5) | 0.28% | — | Nov 15, 2025 | The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘completed_at_operator’ parameter… |
| CVE-2025-58269 | Medium (5.3) | 0.29% | — | Sep 22, 2025 | Use of Hard-coded Credentials vulnerability in weDevs WP Project Manager wedevs-project-manager allows Retrieve Embedded Sensitive Data.This issue affects WP Project Manager: from n/a through <= 2.6.25. |
| CVE-2025-2541 | Medium (5.4) | 0.31% | — | Apr 11, 2025 | The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22 due to insufficient input sanitization and output escaping. This… |
| CVE-2025-3100 | Medium (5.4) | 0.28% | — | Apr 9, 2025 | The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to,… |
| CVE-2025-32280 | High (8.8) | 0.17% | — | Apr 4, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in weDevs WP Project Manager wedevs-project-manager allows Cross Site Request Forgery.This issue affects WP Project Manager: from n/a through < 2.6.25. |
| CVE-2025-22649 | Medium (4.8) | 0.27% | — | Mar 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project Manager wedevs-project-manager allows Stored XSS.This issue affects WP Project Manager: from n/a… |
| CVE-2024-13500 | Medium (6.5) | 0.43% | — | Feb 15, 2025 | The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up… |
| CVE-2024-13752 | Medium (6.5) | 0.52% | — | Feb 15, 2025 | The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check in the… |
| CVE-2024-12195 | Medium (6.5) | 0.43% | — | Jan 4, 2025 | The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to SQL Injection via the 'project_id' parameter of the… |
| CVE-2024-10548 | Medium (6.5) | 0.40% | — | Dec 19, 2024 | The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.15 via the Project Task List ('/wp-json/pm/v2/projects/1/task-lists') REST API… |
| CVE-2023-40003 | Critical (9.8) | 0.50% | — | Dec 13, 2024 | Missing Authorization vulnerability in weDevs WP Project Manager wedevs-project-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Project Manager: from n/a through <=… |
| CVE-2024-10520 | Medium (5.3) | 0.32% | — | Nov 20, 2024 | The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' method of the 'Create_Milestone', 'Create_Task_List', 'Create_Task', and… |
| CVE-2024-10174 | High (7.3) | 0.66% | — | Nov 13, 2024 | The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including,… |
| CVE-2023-49860 | Medium (5.4) | 0.39% | — | Dec 14, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts allows… |
| CVE-2023-34383 | Critical (9.8) | 0.68% | — | Nov 3, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP Project Manager wedevs-project-manager allows SQL Injection.This issue affects WP Project Manager: from n/a… |
| CVE-2023-3636 | High (8.8) | 0.86% | — | Aug 31, 2023 | The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.4 due to insufficient restriction on the 'save_users_map_name' function. This makes it possible for… |
| CVE-2020-36745 | High (8.8) | 0.44% | — | Jul 1, 2023 | The WP Project Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.0. This is due to missing or incorrect nonce validation on the do_updates() function. This… |
| CVE-2021-36826 | Medium (5.4) | 0.62% | — | Apr 4, 2022 | Authenticated (subscriber or higher user role if allowed to access projects) Stored Cross-Site Scripting (XSS) vulnerability in weDevs WP Project Manager plugin <= 2.4.13 versions. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.