CVE-2023-34383
- EPSS 0.55%
- Veröffentlicht 03.11.2023 12:15:08
- Zuletzt bearbeitet 28.04.2026 19:20:45
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP Project Manager wedevs-project-manager allows SQL Injection.This issue affects WP Project Manager: from n/a through 2.6.0.
CVE-2023-3636
- EPSS 0.86%
- Veröffentlicht 31.08.2023 06:15:10
- Zuletzt bearbeitet 08.04.2026 18:18:10
The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.4 due to insufficient restriction on the 'save_users_map_name' function. This makes it possible for authenticated attackers, with ...
CVE-2020-36745
- EPSS 0.44%
- Veröffentlicht 01.07.2023 05:15:15
- Zuletzt bearbeitet 08.04.2026 18:17:10
The WP Project Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.0. This is due to missing or incorrect nonce validation on the do_updates() function. This makes it possible for unauthentic...
CVE-2021-36826
- EPSS 0.61%
- Veröffentlicht 04.04.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:14:09
Authenticated (subscriber or higher user role if allowed to access projects) Stored Cross-Site Scripting (XSS) vulnerability in weDevs WP Project Manager plugin <= 2.4.13 versions.