PT-2026-64241 · WordPress · Php Project Management
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Project Management, Bug and Issue Tracking Plugin for WordPress versions prior to 5.1.0
Description
An issue exists where user-supplied input is not properly sanitized or escaped before being used in a SQL query. This allows unauthenticated attackers to perform SQL injection attacks, which occur when malicious SQL statements are inserted into entry fields for execution. This flaw is exploitable within the standard front-end issue-tracker configuration via the search parameter.
Recommendations
Update Project Management, Bug and Issue Tracking Plugin for WordPress to version 5.1.0 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Php Project Management