Wp project manager
This hub aggregates every CVE we track for Wp project manager, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
20
CVEs tracked
1
Critical
4
High
0
In CISA KEV
Severity distribution
MEDIUM15HIGH4CRITICAL1
Monthly trend
0
2
3
1
2
1
3
0
0
0
0
1
0
0
1
0
0
0
0
0
0
0
1
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Wp project manager.
- CVE-2026-78262WordPress WP Project Manager plugin <= 4.0.6 - PHP Object Injection vulnerability9.8
- CVE-2025-68040WordPress WP Project Manager plugin <= 3.0.1 - Sensitive Data Exposure vulnerability6.5
- CVE-2025-58269WordPress WP Project Manager Plugin <= 2.6.25 - Sensitive Data Exposure Vulnerability5.3
- CVE-2025-2541WP Project Manager <= 2.6.22 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload6.4
- CVE-2025-3100WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.22 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload6.4
- CVE-2025-32280WordPress WP Project Manager plugin < 2.6.25 - Cross Site Request Forgery (CSRF) Vulnerability4.3
- CVE-2025-22649WordPress WP Project Manager plugin <= 2.6.22 - Cross Site Scripting (XSS) vulnerability5.9
- CVE-2024-13500WP Project Manager <= 2.6.17 - Authenticated (Subscriber+) SQL Injection via orderby Parameter6.5
- CVE-2024-13752WP Project Manager <= 2.6.17 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update6.5
- CVE-2024-12195WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.16 - Authenticated (Subscriber+) SQL Injection6.5
- CVE-2024-10548WP Project Manager <= 2.6.15 - Authenticated (Subscriber+) Sensitive Information Exposure via Project Task List REST API6.5
- CVE-2023-40003WordPress WP Project Manager plugin <= 2.6.7 - Broken Access Control vulnerability6.5
- CVE-2024-12015SQL Injection in WordPress Project Manager Plugin7.7
- CVE-2024-10520WP Project Manager <= 2.6.14 - Missing Authorization to Project Milestone and Task Creation/Deletion5.3
- CVE-2024-10174WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.13 - Insecure Direct Object Reference to Unauthenticated Authorization Bypass7.3
Product normalization is registry-driven with AI assist and human review. How it works