WordPress · Php Project Management · CVE-2026-12877
**Name of the Vulnerable Software and Affected Versions**
Project Management, Bug and Issue Tracking Plugin for WordPress versions prior to 5.1.0
**Description**
An issue exists where user-supplied input is not properly sanitized or escaped before being used in a SQL query. This allows unauthenticated attackers to perform SQL injection attacks, which occur when malicious SQL statements are inserted into entry fields for execution. This flaw is exploitable within the standard front-end issue-tracker configuration via the search parameter.
**Recommendations**
Update Project Management, Bug and Issue Tracking Plugin for WordPress to version 5.1.0 or later.