PT-2026-64241 · WordPress · Php Project Management

·

CVE-2026-12877

·

Published

2026-07-24

·

Updated

2026-07-24

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Project Management, Bug and Issue Tracking Plugin for WordPress versions prior to 5.1.0
Description An issue exists where user-supplied input is not properly sanitized or escaped before being used in a SQL query. This allows unauthenticated attackers to perform SQL injection attacks, which occur when malicious SQL statements are inserted into entry fields for execution. This flaw is exploitable within the standard front-end issue-tracker configuration via the search parameter.
Recommendations Update Project Management, Bug and Issue Tracking Plugin for WordPress to version 5.1.0 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12877

Affected Products

Php Project Management