plugin

Wedevs Project Manager Vulnerabilities

45 known security issues reported for the Wedevs Project Manager WordPress plugin. Most recent disclosed Dec 29, 2025.

3 high 19 medium

Running Wedevs Project Manager on your site? Check whether your installed version is affected.

Scan your site free

Project Manager &#8211; AI-Powered Project &amp; Task Manager with Kanban Board &amp; Gantt Chart [wedevs-project-manager] <= 3.0.1 (unfixed)

unknown

[en] Insertion of Sensitive Information Into Sent Data vulnerability in weDevs WP Project Manager wedevs-project-manager allows Retrieve Embedded Sensitive Data.This issue affects WP Project Manager: from n/a through 3.0.1.

Affected:
up to 3.0.1
Fix:
No patched version reported
Disclosed:
Dec 29, 2025

CVE-2025-68040 on NVD →

Project Manager <= 3.0.1 - Authenticated (Subscriber+) Information Exposure

medium

The Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user...

CVSS:
4.3
Affected:
up to 3.0.1
Fixed in:
3.0.2
Disclosed:
Dec 26, 2025

CVE-2025-68040 on NVD →

WP Project Manager <= 2.6.26 - Authenticated (Subscriber+) SQL Injection via 'completed_at_operator'

medium

The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘completed_at_operator’ parameter in all versions up to, and including, 2.6.26 due to insufficient escaping on the user supplied param...

CVSS:
6.5
Affected:
up to 2.6.26
Fixed in:
2.6.27
Disclosed:
Nov 14, 2025

CVE-2025-8994 on NVD →

WP Project Manager <= 2.6.25 - Unauthenticated Sensitive Information Exposure

medium

The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.25. This makes it possible for unauthenticated attackers to extract sensitive user or configur...

CVSS:
5.3
Affected:
up to 2.6.25
Fixed in:
2.6.26
Disclosed:
Sep 22, 2025

CVE-2025-58269 on NVD →

WP Project Manager <= 2.6.22 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

medium

The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitra...

CVSS:
6.4
Affected:
up to 2.6.22
Fixed in:
2.6.23
Disclosed:
Apr 10, 2025

CVE-2025-2541 on NVD →

WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.22 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload

medium

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22 due to insufficient input sanitization and output escaping in tasks discussion. T...

CVSS:
6.4
Affected:
up to 2.6.22
Fixed in:
2.6.23
Disclosed:
Apr 8, 2025

CVE-2025-3100 on NVD →

WP Project Manager <= 2.6.24 - Cross-Site Request Forgery

medium

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.24. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthe...

CVSS:
4.3
Affected:
up to 2.6.24
Fixed in:
2.6.25
Disclosed:
Apr 4, 2025

CVE-2025-32280 on NVD →

Project Manager &#8211; AI-Powered Project &amp; Task Manager with Kanban Board &amp; Gantt Chart [wedevs-project-manager] <= 2.6.24 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in weDevs WP Project Manager allows Cross Site Request Forgery. This issue affects WP Project Manager: from n/a through 2.6.22.

Affected:
up to 2.6.24
Fix:
No patched version reported
Disclosed:
Apr 4, 2025

CVE-2025-32280 on NVD →

Project Manager &#8211; AI-Powered Project &amp; Task Manager with Kanban Board &amp; Gantt Chart [wedevs-project-manager] < 2.6.23

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project Manager wedevs-project-manager allows Stored XSS.This issue affects WP Project Manager: from n/a through 2.6.22.

Affected:
up to 2.6.23
Fixed in:
2.6.23
Disclosed:
Mar 27, 2025

CVE-2025-22649 on NVD →

Project Manager &#8211; AI-Powered Project &amp; Task Manager with Kanban Board &amp; Gantt Chart [wedevs-project-manager] < 2.6.18

unknown

[en] The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check in the '/pm/v2/settings/notice' endpoint all versions up to, and including, 2.6.17. This makes it possible for...

Affected:
up to 2.6.18
Fixed in:
2.6.18
Disclosed:
Feb 15, 2025

CVE-2024-13752 on NVD →

Project Manager &#8211; AI-Powered Project &amp; Task Manager with Kanban Board &amp; Gantt Chart [wedevs-project-manager] < 2.6.18

unknown

[en] The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.6.17 due to insufficient escaping on the user supplied parameter and lack of...

Affected:
up to 2.6.18
Fixed in:
2.6.18
Disclosed:
Feb 15, 2025

CVE-2024-13500 on NVD →

WP Project Manager <= 2.6.17 - Authenticated (Subscriber+) SQL Injection via orderby Parameter

medium

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.6.17 due to insufficient escaping on the user supplied parameter and lack of suffi...

CVSS:
6.5
Affected:
up to 2.6.17
Fixed in:
2.6.18
Disclosed:
Feb 14, 2025

CVE-2024-13500 on NVD →

WP Project Manager <= 2.6.17 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update

medium

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check in the '/pm/v2/settings/notice' endpoint all versions up to, and including, 2.6.17. This makes it possible for auth...

CVSS:
6.5
Affected:
up to 2.6.17
Fixed in:
2.6.18
Disclosed:
Feb 14, 2025

CVE-2024-13752 on NVD →

WP Project Manager <= 2.6.22 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in...

CVSS:
4.4
Affected:
up to 2.6.22
Fixed in:
2.6.23
Disclosed:
Feb 3, 2025

CVE-2025-22649 on NVD →

Project Manager &#8211; AI-Powered Project &amp; Task Manager with Kanban Board &amp; Gantt Chart [wedevs-project-manager] < 2.6.17

unknown

[en] The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to SQL Injection via the 'project_id' parameter of the /wp-json/pm/v2/projects/2/task-lists REST API endpoint in all versions up to, and including, 2.6.16 due to insufficien...

Affected:
up to 2.6.17
Fixed in:
2.6.17
Disclosed:
Jan 4, 2025

CVE-2024-12195 on NVD →

WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.16 - Authenticated (Subscriber+) SQL Injection

medium

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to SQL Injection via the 'project_id' parameter of the /wp-json/pm/v2/projects/2/task-lists REST API endpoint in all versions up to, and including, 2.6.16 due to insufficient esc...

CVSS:
6.5
Affected:
up to 2.6.16
Fixed in:
2.6.17
Disclosed:
Jan 3, 2025

CVE-2024-12195 on NVD →

Project Manager &#8211; AI-Powered Project &amp; Task Manager with Kanban Board &amp; Gantt Chart [wedevs-project-manager] < 2.6.16

unknown

[en] The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.15 via the Project Task List ('/wp-json/pm/v2/projects/1/task-lists') REST API endpoint. This makes it possible for authenticated attackers, with Subscriber-level access and above,...

Affected:
up to 2.6.16
Fixed in:
2.6.16
Disclosed:
Dec 19, 2024

CVE-2024-10548 on NVD →

WP Project Manager <= 2.6.15 - Authenticated (Subscriber+) Sensitive Information Exposure via Project Task List REST API

medium

The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.15 via the Project Task List ('/wp-json/pm/v2/projects/1/task-lists') REST API endpoint. This makes it possible for authenticated attackers, with Subscriber-level access and above, to ex...

CVSS:
6.5
Affected:
up to 2.6.15
Fixed in:
2.6.16
Disclosed:
Dec 18, 2024

CVE-2024-10548 on NVD →

Project Manager &#8211; AI-Powered Project &amp; Task Manager with Kanban Board &amp; Gantt Chart [wedevs-project-manager] < 2.6.8

unknown

[en] Missing Authorization vulnerability in weDevs WP Project Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Project Manager: from n/a through 2.6.7.

Affected:
up to 2.6.8
Fixed in:
2.6.8
Disclosed:
Dec 13, 2024

CVE-2023-40003 on NVD →

WP Project Manager <= 2.6.31 - Authenticated (Project Manager+) SQL Injection

medium

The WP Project Manager plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in the '/pm/v2/activites' route in all versions up to, and including, 2.6.31 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it pos...

CVSS:
6.5
Affected:
up to 2.6.31
Fixed in:
3.0.0
Disclosed:
Dec 2, 2024

CVE-2024-12015 on NVD →

Project Manager &#8211; AI-Powered Project &amp; Task Manager with Kanban Board &amp; Gantt Chart [wedevs-project-manager] < 2.6.14

unknown

[en] The 'Project Manager' WordPress Plugin is affected by an authenticated SQL injection vulnerability in the 'orderby' parameter in the '/pm/v2/activites' route.

Affected:
up to 2.6.14
Fixed in:
2.6.14
Disclosed:
Dec 2, 2024

CVE-2024-12015 on NVD →

Project Manager &#8211; AI-Powered Project &amp; Task Manager with Kanban Board &amp; Gantt Chart [wedevs-project-manager] < 2.6.15

unknown

[en] The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' method of the 'Create_Milestone', 'Create_Task_List', 'Create_Task', and 'Delete_Task' classes in version 2.6.14. This makes it possible for unauthenticated attackers to c...

Affected:
up to 2.6.15
Fixed in:
2.6.15
Disclosed:
Nov 20, 2024

CVE-2024-10520 on NVD →

WP Project Manager <= 2.6.14 - Missing Authorization to Project Milestone and Task Creation/Deletion

medium

The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' method of the 'Create_Milestone', 'Create_Task_List', 'Create_Task', and 'Delete_Task' classes in version 2.6.14. This makes it possible for unauthenticated attackers to create...

CVSS:
5.3
Affected:
up to 2.6.14
Fixed in:
2.6.15
Disclosed:
Nov 19, 2024

CVE-2024-10520 on NVD →

Project Manager &#8211; AI-Powered Project &amp; Task Manager with Kanban Board &amp; Gantt Chart [wedevs-project-manager] < 2.6.14

unknown

[en] The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.13 via the 'Abstract_Permission' class due to missing validation on the 'user_id' user controll...

Affected:
up to 2.6.14
Fixed in:
2.6.14
Disclosed:
Nov 13, 2024

CVE-2024-10174 on NVD →

WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.13 - Insecure Direct Object Reference to Unauthenticated Authorization Bypass

high

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.13 via the 'Abstract_Permission' class due to missing validation on the 'user_id' user controlled ke...

CVSS:
7.3
Affected:
up to 2.6.13
Fixed in:
2.6.14
Disclosed:
Nov 12, 2024

CVE-2024-10174 on NVD →

Project Manager &#8211; AI-Powered Project &amp; Task Manager with Kanban Board &amp; Gantt Chart [wedevs-project-manager] < 2.6.9

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts allows Stored XSS.This issue affects WP Project Manager – Task, team, and project management plugin fea...

Affected:
up to 2.6.9
Fixed in:
2.6.9
Disclosed:
Dec 14, 2023

CVE-2023-49860 on NVD →

WP Project Manager <= 2.6.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in page...

CVSS:
6.4
Affected:
up to 2.6.8
Fixed in:
2.6.9
Disclosed:
Dec 7, 2023

CVE-2023-49860 on NVD →

WP Project Manager <= 2.6.7 - Missing Authorization

medium

The WP Project Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an unknown function in versions up to, and including, 2.6.7. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.6.7
Fixed in:
2.6.8
Disclosed:
Dec 7, 2023

CVE-2023-40003 on NVD →

Project Manager &#8211; AI-Powered Project &amp; Task Manager with Kanban Board &amp; Gantt Chart [wedevs-project-manager] < 2.6.1

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP Project Manager wedevs-project-manager allows SQL Injection.This issue affects WP Project Manager: from n/a through 2.6.0.

Affected:
up to 2.6.1
Fixed in:
2.6.1
Disclosed:
Nov 3, 2023

CVE-2023-34383 on NVD →

WP Project Manager <= 2.6.0 - Authenticated (Subscriber+) SQL Injection

high

The WP Project Manager plugin for WordPress is vulnerable to SQL Injection via the user task starting date in versions up to, and including, 2.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers...

CVSS:
8.8
Affected:
up to 2.6.0
Fixed in:
2.6.1
Disclosed:
Sep 4, 2023

CVE-2023-34383 on NVD →

Project Manager &#8211; AI-Powered Project &amp; Task Manager with Kanban Board &amp; Gantt Chart [wedevs-project-manager] < 2.6.5

unknown

[en] The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.4 due to insufficient restriction on the 'save_users_map_name' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user ro...

Affected:
up to 2.6.5
Fixed in:
2.6.5
Disclosed:
Aug 31, 2023

CVE-2023-3636 on NVD →

WP Project Manager <= 2.6.4 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation

high

The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.4 due to insufficient restriction on the 'save_users_map_name' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by...

CVSS:
8.8
Affected:
up to 2.6.4
Fixed in:
2.6.5
Disclosed:
Jul 24, 2023

CVE-2023-3636 on NVD →

Project Manager &#8211; AI-Powered Project &amp; Task Manager with Kanban Board &amp; Gantt Chart [wedevs-project-manager] < 2.4.1

unknown

[en] The WP Project Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.0. This is due to missing or incorrect nonce validation on the do_updates() function. This makes it possible for unauthenticated attackers to trigger updates via a forged request granted th...

Affected:
up to 2.4.1
Fixed in:
2.4.1
Disclosed:
Jul 1, 2023

CVE-2020-36745 on NVD →

Project Manager &#8211; AI-Powered Project &amp; Task Manager with Kanban Board &amp; Gantt Chart [wedevs-project-manager] < 2.4.10

unknown
Affected:
up to 2.4.10
Fixed in:
2.4.10
Disclosed:
Jun 7, 2023

CVE-2021-4342 on NVD →

Appsero <= 1.2.1 - Missing Authorization

medium

The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with subscriber-level permissio...

CVSS:
4.3
Affected:
up to 2.6.12
Fixed in:
2.6.13
Disclosed:
Dec 16, 2022

Appsero <= 1.2.0 - Cross-Site Request Forgery

medium

The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to invoke this function inten...

CVSS:
4.3
Affected:
up to 2.6.12
Fixed in:
2.6.13
Disclosed:
Dec 14, 2022

CVE-2022-47150 on NVD →

Project Manager &#8211; AI-Powered Project &amp; Task Manager with Kanban Board &amp; Gantt Chart [wedevs-project-manager] < 2.4.14

unknown

[en] Authenticated (subscriber or higher user role if allowed to access projects) Stored Cross-Site Scripting (XSS) vulnerability in weDevs WP Project Manager plugin <= 2.4.13 versions.

Affected:
up to 2.4.14
Fixed in:
2.4.14
Disclosed:
Apr 4, 2022

CVE-2021-36826 on NVD →

WP Project Manager <= 2.4.13 - Authenticated Stored Cross-Site Scripting

medium

The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.13 due to insufficient input sanitization and output escaping. This makes it possible for Subscriber-level attackers to inject arbitrary web scripts in pages that will execute whenever a user a...

CVSS:
5.4
Affected:
up to 2.4.13
Fixed in:
2.4.14
Disclosed:
Oct 11, 2021

CVE-2021-36826 on NVD →

Project Manager &#8211; AI-Powered Project &amp; Task Manager with Kanban Board &amp; Gantt Chart [wedevs-project-manager] < 2.4.10

unknown

Cross-Site Request Forgery (CSRF) vulnerability found by NintechNet in WordPress WP Project Manager plugin (versions <= 2.4.9).

Affected:
up to 2.4.10
Fixed in:
2.4.10
Disclosed:
Mar 1, 2021

WP Project Manager <= 2.4.0 - Cross-Site Request Forgery Bypass

medium

The WP Project Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.0. This is due to missing or incorrect nonce validation on the do_updates() function. This makes it possible for unauthenticated attackers to trigger updates via a forged request granted they ca...

CVSS:
4.3
Affected:
up to 2.4.1
Fixed in:
2.4.1
Disclosed:
Sep 16, 2020

CVE-2020-36745 on NVD →

Project Manager &#8211; AI-Powered Project &amp; Task Manager with Kanban Board &amp; Gantt Chart [wedevs-project-manager] < 2.4.1

unknown

Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress WP Project Manager plugin (versions <= 2.4.0).

Affected:
up to 2.4.1
Fixed in:
2.4.1
Disclosed:
Sep 16, 2020

Project Manager &#8211; AI-Powered Project &amp; Task Manager with Kanban Board &amp; Gantt Chart [wedevs-project-manager] < 2.6.1

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 2.6.1
Fixed in:
2.6.1

CVE-2022-47150 on NVD →

Project Manager &#8211; AI-Powered Project &amp; Task Manager with Kanban Board &amp; Gantt Chart [wedevs-project-manager] < 2.4.10

unknown

Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.

Affected:
up to 2.4.10
Fixed in:
2.4.10

Project Manager &#8211; AI-Powered Project &amp; Task Manager with Kanban Board &amp; Gantt Chart [wedevs-project-manager] < 2.6.23

unknown
Affected:
up to 2.6.23
Fixed in:
2.6.23

CVE-2025-3100 on NVD →

Project Manager &#8211; AI-Powered Project &amp; Task Manager with Kanban Board &amp; Gantt Chart [wedevs-project-manager] < 2.6.23

unknown
Affected:
up to 2.6.23
Fixed in:
2.6.23

CVE-2025-2541 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database