Wedevs

Wp Project Manager

24 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 01.10.2026 14:34:02
  • Zuletzt bearbeitet 01.10.2026 20:25:35

Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions.

  • EPSS 0.23%
  • Veröffentlicht 25.08.2026 05:31:28
  • Zuletzt bearbeitet 28.09.2026 23:10:00

The WP Project Manager Pro plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This...

  • EPSS 0.33%
  • Veröffentlicht 24.08.2026 21:31:30
  • Zuletzt bearbeitet 27.08.2026 17:20:38

Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.

  • EPSS 0.28%
  • Veröffentlicht 24.08.2026 12:16:51
  • Zuletzt bearbeitet 24.08.2026 16:40:53

Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.

  • EPSS 0.23%
  • Veröffentlicht 29.12.2025 23:25:11
  • Zuletzt bearbeitet 07.10.2026 12:10:00

Insertion of Sensitive Information Into Sent Data vulnerability in weDevs WP Project Manager wedevs-project-manager allows Retrieve Embedded Sensitive Data.This issue affects WP Project Manager: from n/a through <= 3.0.1.

  • EPSS 0.28%
  • Veröffentlicht 15.11.2025 05:45:33
  • Zuletzt bearbeitet 07.10.2026 21:10:00

The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘completed_at_operator’ parameter in all versions up to, and inc...

  • EPSS 0.27%
  • Veröffentlicht 22.09.2025 18:23:15
  • Zuletzt bearbeitet 30.09.2026 23:10:00

Use of Hard-coded Credentials vulnerability in weDevs WP Project Manager wedevs-project-manager allows Retrieve Embedded Sensitive Data.This issue affects WP Project Manager: from n/a through <= 2.6.25.

  • EPSS 0.3%
  • Veröffentlicht 11.04.2025 11:11:56
  • Zuletzt bearbeitet 06.05.2025 14:09:58

The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22 due to insufficient input sanitization and output escaping. This makes it possible for authenti...

  • EPSS 0.27%
  • Veröffentlicht 09.04.2025 04:21:20
  • Zuletzt bearbeitet 14.07.2025 17:27:25

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22 due to insu...

  • EPSS 0.17%
  • Veröffentlicht 04.04.2025 16:15:39
  • Zuletzt bearbeitet 23.04.2026 15:28:53

Cross-Site Request Forgery (CSRF) vulnerability in weDevs WP Project Manager wedevs-project-manager allows Cross Site Request Forgery.This issue affects WP Project Manager: from n/a through < 2.6.25.