Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart [wedevs-project-manager] <= 3.0.1 (unfixed)
unknown
[en] Insertion of Sensitive Information Into Sent Data vulnerability in weDevs WP Project Manager wedevs-project-manager allows Retrieve Embedded Sensitive Data.This issue affects WP Project Manager: from n/a through 3.0.1.
- Affected:
- up to 3.0.1
- Fix:
- No patched version reported
- Disclosed:
- Dec 29, 2025
CVE-2025-68040 on NVD →
Project Manager <= 3.0.1 - Authenticated (Subscriber+) Information Exposure
medium
The Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user...
- CVSS:
- 4.3
- Affected:
- up to 3.0.1
- Fixed in:
- 3.0.2
- Disclosed:
- Dec 26, 2025
CVE-2025-68040 on NVD →
WP Project Manager <= 2.6.26 - Authenticated (Subscriber+) SQL Injection via 'completed_at_operator'
medium
The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘completed_at_operator’ parameter in all versions up to, and including, 2.6.26 due to insufficient escaping on the user supplied param...
- CVSS:
- 6.5
- Affected:
- up to 2.6.26
- Fixed in:
- 2.6.27
- Disclosed:
- Nov 14, 2025
CVE-2025-8994 on NVD →
WP Project Manager <= 2.6.25 - Unauthenticated Sensitive Information Exposure
medium
The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.25. This makes it possible for unauthenticated attackers to extract sensitive user or configur...
- CVSS:
- 5.3
- Affected:
- up to 2.6.25
- Fixed in:
- 2.6.26
- Disclosed:
- Sep 22, 2025
CVE-2025-58269 on NVD →
WP Project Manager <= 2.6.22 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
medium
The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitra...
- CVSS:
- 6.4
- Affected:
- up to 2.6.22
- Fixed in:
- 2.6.23
- Disclosed:
- Apr 10, 2025
CVE-2025-2541 on NVD →
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.22 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload
medium
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22 due to insufficient input sanitization and output escaping in tasks discussion. T...
- CVSS:
- 6.4
- Affected:
- up to 2.6.22
- Fixed in:
- 2.6.23
- Disclosed:
- Apr 8, 2025
CVE-2025-3100 on NVD →
WP Project Manager <= 2.6.24 - Cross-Site Request Forgery
medium
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.24. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthe...
- CVSS:
- 4.3
- Affected:
- up to 2.6.24
- Fixed in:
- 2.6.25
- Disclosed:
- Apr 4, 2025
CVE-2025-32280 on NVD →
Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart [wedevs-project-manager] <= 2.6.24 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in weDevs WP Project Manager allows Cross Site Request Forgery. This issue affects WP Project Manager: from n/a through 2.6.22.
- Affected:
- up to 2.6.24
- Fix:
- No patched version reported
- Disclosed:
- Apr 4, 2025
CVE-2025-32280 on NVD →
Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart [wedevs-project-manager] < 2.6.23
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project Manager wedevs-project-manager allows Stored XSS.This issue affects WP Project Manager: from n/a through 2.6.22.
- Affected:
- up to 2.6.23
- Fixed in:
- 2.6.23
- Disclosed:
- Mar 27, 2025
CVE-2025-22649 on NVD →
Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart [wedevs-project-manager] < 2.6.18
unknown
[en] The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check in the '/pm/v2/settings/notice' endpoint all versions up to, and including, 2.6.17. This makes it possible for...
- Affected:
- up to 2.6.18
- Fixed in:
- 2.6.18
- Disclosed:
- Feb 15, 2025
CVE-2024-13752 on NVD →
Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart [wedevs-project-manager] < 2.6.18
unknown
[en] The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.6.17 due to insufficient escaping on the user supplied parameter and lack of...
- Affected:
- up to 2.6.18
- Fixed in:
- 2.6.18
- Disclosed:
- Feb 15, 2025
CVE-2024-13500 on NVD →
WP Project Manager <= 2.6.17 - Authenticated (Subscriber+) SQL Injection via orderby Parameter
medium
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.6.17 due to insufficient escaping on the user supplied parameter and lack of suffi...
- CVSS:
- 6.5
- Affected:
- up to 2.6.17
- Fixed in:
- 2.6.18
- Disclosed:
- Feb 14, 2025
CVE-2024-13500 on NVD →
WP Project Manager <= 2.6.17 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update
medium
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check in the '/pm/v2/settings/notice' endpoint all versions up to, and including, 2.6.17. This makes it possible for auth...
- CVSS:
- 6.5
- Affected:
- up to 2.6.17
- Fixed in:
- 2.6.18
- Disclosed:
- Feb 14, 2025
CVE-2024-13752 on NVD →
WP Project Manager <= 2.6.22 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in...
- CVSS:
- 4.4
- Affected:
- up to 2.6.22
- Fixed in:
- 2.6.23
- Disclosed:
- Feb 3, 2025
CVE-2025-22649 on NVD →
Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart [wedevs-project-manager] < 2.6.17
unknown
[en] The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to SQL Injection via the 'project_id' parameter of the /wp-json/pm/v2/projects/2/task-lists REST API endpoint in all versions up to, and including, 2.6.16 due to insufficien...
- Affected:
- up to 2.6.17
- Fixed in:
- 2.6.17
- Disclosed:
- Jan 4, 2025
CVE-2024-12195 on NVD →
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.16 - Authenticated (Subscriber+) SQL Injection
medium
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to SQL Injection via the 'project_id' parameter of the /wp-json/pm/v2/projects/2/task-lists REST API endpoint in all versions up to, and including, 2.6.16 due to insufficient esc...
- CVSS:
- 6.5
- Affected:
- up to 2.6.16
- Fixed in:
- 2.6.17
- Disclosed:
- Jan 3, 2025
CVE-2024-12195 on NVD →
Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart [wedevs-project-manager] < 2.6.16
unknown
[en] The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.15 via the Project Task List ('/wp-json/pm/v2/projects/1/task-lists') REST API endpoint. This makes it possible for authenticated attackers, with Subscriber-level access and above,...
- Affected:
- up to 2.6.16
- Fixed in:
- 2.6.16
- Disclosed:
- Dec 19, 2024
CVE-2024-10548 on NVD →
WP Project Manager <= 2.6.15 - Authenticated (Subscriber+) Sensitive Information Exposure via Project Task List REST API
medium
The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.15 via the Project Task List ('/wp-json/pm/v2/projects/1/task-lists') REST API endpoint. This makes it possible for authenticated attackers, with Subscriber-level access and above, to ex...
- CVSS:
- 6.5
- Affected:
- up to 2.6.15
- Fixed in:
- 2.6.16
- Disclosed:
- Dec 18, 2024
CVE-2024-10548 on NVD →
Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart [wedevs-project-manager] < 2.6.8
unknown
[en] Missing Authorization vulnerability in weDevs WP Project Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Project Manager: from n/a through 2.6.7.
- Affected:
- up to 2.6.8
- Fixed in:
- 2.6.8
- Disclosed:
- Dec 13, 2024
CVE-2023-40003 on NVD →
WP Project Manager <= 2.6.31 - Authenticated (Project Manager+) SQL Injection
medium
The WP Project Manager plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in the '/pm/v2/activites' route in all versions up to, and including, 2.6.31 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it pos...
- CVSS:
- 6.5
- Affected:
- up to 2.6.31
- Fixed in:
- 3.0.0
- Disclosed:
- Dec 2, 2024
CVE-2024-12015 on NVD →
Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart [wedevs-project-manager] < 2.6.14
unknown
[en] The 'Project Manager' WordPress Plugin is affected by an authenticated SQL injection vulnerability in the 'orderby' parameter in the '/pm/v2/activites' route.
- Affected:
- up to 2.6.14
- Fixed in:
- 2.6.14
- Disclosed:
- Dec 2, 2024
CVE-2024-12015 on NVD →
Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart [wedevs-project-manager] < 2.6.15
unknown
[en] The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' method of the 'Create_Milestone', 'Create_Task_List', 'Create_Task', and 'Delete_Task' classes in version 2.6.14. This makes it possible for unauthenticated attackers to c...
- Affected:
- up to 2.6.15
- Fixed in:
- 2.6.15
- Disclosed:
- Nov 20, 2024
CVE-2024-10520 on NVD →
WP Project Manager <= 2.6.14 - Missing Authorization to Project Milestone and Task Creation/Deletion
medium
The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' method of the 'Create_Milestone', 'Create_Task_List', 'Create_Task', and 'Delete_Task' classes in version 2.6.14. This makes it possible for unauthenticated attackers to create...
- CVSS:
- 5.3
- Affected:
- up to 2.6.14
- Fixed in:
- 2.6.15
- Disclosed:
- Nov 19, 2024
CVE-2024-10520 on NVD →
Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart [wedevs-project-manager] < 2.6.14
unknown
[en] The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.13 via the 'Abstract_Permission' class due to missing validation on the 'user_id' user controll...
- Affected:
- up to 2.6.14
- Fixed in:
- 2.6.14
- Disclosed:
- Nov 13, 2024
CVE-2024-10174 on NVD →
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.13 - Insecure Direct Object Reference to Unauthenticated Authorization Bypass
high
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.13 via the 'Abstract_Permission' class due to missing validation on the 'user_id' user controlled ke...
- CVSS:
- 7.3
- Affected:
- up to 2.6.13
- Fixed in:
- 2.6.14
- Disclosed:
- Nov 12, 2024
CVE-2024-10174 on NVD →
Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart [wedevs-project-manager] < 2.6.9
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts allows Stored XSS.This issue affects WP Project Manager – Task, team, and project management plugin fea...
- Affected:
- up to 2.6.9
- Fixed in:
- 2.6.9
- Disclosed:
- Dec 14, 2023
CVE-2023-49860 on NVD →
WP Project Manager <= 2.6.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in page...
- CVSS:
- 6.4
- Affected:
- up to 2.6.8
- Fixed in:
- 2.6.9
- Disclosed:
- Dec 7, 2023
CVE-2023-49860 on NVD →
WP Project Manager <= 2.6.7 - Missing Authorization
medium
The WP Project Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an unknown function in versions up to, and including, 2.6.7. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.6.7
- Fixed in:
- 2.6.8
- Disclosed:
- Dec 7, 2023
CVE-2023-40003 on NVD →
Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart [wedevs-project-manager] < 2.6.1
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP Project Manager wedevs-project-manager allows SQL Injection.This issue affects WP Project Manager: from n/a through 2.6.0.
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.1
- Disclosed:
- Nov 3, 2023
CVE-2023-34383 on NVD →
WP Project Manager <= 2.6.0 - Authenticated (Subscriber+) SQL Injection
high
The WP Project Manager plugin for WordPress is vulnerable to SQL Injection via the user task starting date in versions up to, and including, 2.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers...
- CVSS:
- 8.8
- Affected:
- up to 2.6.0
- Fixed in:
- 2.6.1
- Disclosed:
- Sep 4, 2023
CVE-2023-34383 on NVD →
Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart [wedevs-project-manager] < 2.6.5
unknown
[en] The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.4 due to insufficient restriction on the 'save_users_map_name' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user ro...
- Affected:
- up to 2.6.5
- Fixed in:
- 2.6.5
- Disclosed:
- Aug 31, 2023
CVE-2023-3636 on NVD →
WP Project Manager <= 2.6.4 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation
high
The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.4 due to insufficient restriction on the 'save_users_map_name' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by...
- CVSS:
- 8.8
- Affected:
- up to 2.6.4
- Fixed in:
- 2.6.5
- Disclosed:
- Jul 24, 2023
CVE-2023-3636 on NVD →
Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart [wedevs-project-manager] < 2.4.1
unknown
[en] The WP Project Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.0. This is due to missing or incorrect nonce validation on the do_updates() function. This makes it possible for unauthenticated attackers to trigger updates via a forged request granted th...
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.1
- Disclosed:
- Jul 1, 2023
CVE-2020-36745 on NVD →
Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart [wedevs-project-manager] < 2.4.10
unknown
- Affected:
- up to 2.4.10
- Fixed in:
- 2.4.10
- Disclosed:
- Jun 7, 2023
CVE-2021-4342 on NVD →
Appsero <= 1.2.1 - Missing Authorization
medium
The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with subscriber-level permissio...
- CVSS:
- 4.3
- Affected:
- up to 2.6.12
- Fixed in:
- 2.6.13
- Disclosed:
- Dec 16, 2022
Appsero <= 1.2.0 - Cross-Site Request Forgery
medium
The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to invoke this function inten...
- CVSS:
- 4.3
- Affected:
- up to 2.6.12
- Fixed in:
- 2.6.13
- Disclosed:
- Dec 14, 2022
CVE-2022-47150 on NVD →
Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart [wedevs-project-manager] < 2.4.14
unknown
[en] Authenticated (subscriber or higher user role if allowed to access projects) Stored Cross-Site Scripting (XSS) vulnerability in weDevs WP Project Manager plugin <= 2.4.13 versions.
- Affected:
- up to 2.4.14
- Fixed in:
- 2.4.14
- Disclosed:
- Apr 4, 2022
CVE-2021-36826 on NVD →
WP Project Manager <= 2.4.13 - Authenticated Stored Cross-Site Scripting
medium
The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.13 due to insufficient input sanitization and output escaping. This makes it possible for Subscriber-level attackers to inject arbitrary web scripts in pages that will execute whenever a user a...
- CVSS:
- 5.4
- Affected:
- up to 2.4.13
- Fixed in:
- 2.4.14
- Disclosed:
- Oct 11, 2021
CVE-2021-36826 on NVD →
Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart [wedevs-project-manager] < 2.4.10
unknown
Cross-Site Request Forgery (CSRF) vulnerability found by NintechNet in WordPress WP Project Manager plugin (versions <= 2.4.9).
- Affected:
- up to 2.4.10
- Fixed in:
- 2.4.10
- Disclosed:
- Mar 1, 2021
WP Project Manager <= 2.4.0 - Cross-Site Request Forgery Bypass
medium
The WP Project Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.0. This is due to missing or incorrect nonce validation on the do_updates() function. This makes it possible for unauthenticated attackers to trigger updates via a forged request granted they ca...
- CVSS:
- 4.3
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.1
- Disclosed:
- Sep 16, 2020
CVE-2020-36745 on NVD →
Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart [wedevs-project-manager] < 2.4.1
unknown
Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress WP Project Manager plugin (versions <= 2.4.0).
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.1
- Disclosed:
- Sep 16, 2020
Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart [wedevs-project-manager] < 2.6.1
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.1
CVE-2022-47150 on NVD →
Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart [wedevs-project-manager] < 2.4.10
unknown
Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.
- Affected:
- up to 2.4.10
- Fixed in:
- 2.4.10
Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart [wedevs-project-manager] < 2.6.23
unknown
- Affected:
- up to 2.6.23
- Fixed in:
- 2.6.23
CVE-2025-3100 on NVD →
Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart [wedevs-project-manager] < 2.6.23
unknown
- Affected:
- up to 2.6.23
- Fixed in:
- 2.6.23
CVE-2025-2541 on NVD →