Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

23 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.3)0.25%—Wedevs WP Project ManagerAI1/10/20261/10/2026
Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions.
AplazadaMedia (6.5)0.38%—WP Project Manager PROAI25/8/202628/9/2026
The WP Project Manager Pro plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level…
AplazadaCrítica (9.8)0.56%—Wedevs WP Project ManagerAI24/8/202627/8/2026
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
AplazadaAlta (8.5)0.36%—WP Project Manager PROAI24/8/202624/8/2026
Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.
AplazadaMedia (6.5)0.26%—Wedevs WP Project ManagerAI29/12/20251/10/2026
Insertion of Sensitive Information Into Sent Data vulnerability in weDevs WP Project Manager wedevs-project-manager allows Retrieve Embedded Sensitive Data.This issue affects WP Project Manager: from n/a through <= 3.0.1.
AplazadaMedia (6.5)0.28%—Wedevs WP Project ManagerAI15/11/202517/6/2026
The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘completed_at_operator’ parameter in all versions up to, and including, 2.6.26 due to insufficient escaping on the user supplied…
AplazadaMedia (5.3)0.29%—Wedevs WP Project ManagerAI22/9/202530/9/2026
Use of Hard-coded Credentials vulnerability in weDevs WP Project Manager wedevs-project-manager allows Retrieve Embedded Sensitive Data.This issue affects WP Project Manager: from n/a through <= 2.6.25.
AnalizadaMedia (5.4)0.31%—Wedevs WP Project Manager11/4/202517/6/2026
The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject…
AnalizadaMedia (5.4)0.28%—Wedevs WP Project Manager9/4/202517/6/2026
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22 due to insufficient input sanitization and output escaping in tasks discussion.…
ModificadaAlta (8.8)0.17%—Wedevs WP Project Manager4/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in weDevs WP Project Manager wedevs-project-manager allows Cross Site Request Forgery.This issue affects WP Project Manager: from n/a through < 2.6.25.
ModificadaMedia (4.8)0.27%—Wedevs WP Project Manager27/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project Manager wedevs-project-manager allows Stored XSS.This issue affects WP Project Manager: from n/a through <= 2.6.22.
AnalizadaMedia (6.5)0.43%—Wedevs WP Project Manager15/2/202517/6/2026
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.6.17 due to insufficient escaping on the user supplied parameter and lack of…
AnalizadaMedia (6.5)0.52%—Wedevs WP Project Manager15/2/202517/6/2026
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check in the '/pm/v2/settings/notice' endpoint all versions up to, and including, 2.6.17. This makes it possible for…
AnalizadaMedia (6.5)0.43%—Wedevs WP Project Manager4/1/202517/6/2026
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to SQL Injection via the 'project_id' parameter of the /wp-json/pm/v2/projects/2/task-lists REST API endpoint in all versions up to, and including, 2.6.16 due to insufficient…
AnalizadaMedia (6.5)0.40%—Wedevs WP Project Manager19/12/202417/6/2026
The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.15 via the Project Task List ('/wp-json/pm/v2/projects/1/task-lists') REST API endpoint. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…
ModificadaCrítica (9.8)0.50%—Wedevs WP Project Manager13/12/202417/6/2026
Missing Authorization vulnerability in weDevs WP Project Manager wedevs-project-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Project Manager: from n/a through <= 2.6.7.
AnalizadaMedia (5.3)0.32%—Wedevs WP Project Manager20/11/202417/6/2026
The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' method of the 'Create_Milestone', 'Create_Task_List', 'Create_Task', and 'Delete_Task' classes in version 2.6.14. This makes it possible for unauthenticated attackers to…
AnalizadaAlta (7.3)0.66%—Wedevs WP Project Manager13/11/202417/6/2026
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.13 via the 'Abstract_Permission' class due to missing validation on the 'user_id' user controlled…
ModificadaMedia (5.4)0.39%—Wedevs WP Project Manager14/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts allows Stored XSS.This issue affects WP Project Manager – Task, team, and project management plugin…
ModificadaCrítica (9.8)0.68%—Wedevs WP Project Manager3/11/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP Project Manager wedevs-project-manager allows SQL Injection.This issue affects WP Project Manager: from n/a through 2.6.0.
ModificadaAlta (8.8)0.86%—Wedevs WP Project Manager31/8/202317/6/2026
The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.4 due to insufficient restriction on the 'save_users_map_name' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role…
ModificadaAlta (8.8)0.44%—Wedevs WP Project Manager1/7/202317/6/2026
The WP Project Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.0. This is due to missing or incorrect nonce validation on the do_updates() function. This makes it possible for unauthenticated attackers to trigger updates via a forged request granted they…
ModificadaMedia (5.4)0.62%—Wedevs WP Project Manager4/4/202217/6/2026
Authenticated (subscriber or higher user role if allowed to access projects) Stored Cross-Site Scripting (XSS) vulnerability in weDevs WP Project Manager plugin <= 2.4.13 versions.