PT-2026-81958 · WordPress · Project Manager

·

CVE-2026-74928

·

Published

2026-08-26

·

Updated

2026-08-26

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Project Manager WordPress plugin versions prior to 4.0.7
Description Lack of authorization checks on import routes allows unauthenticated users to create WordPress accounts using passwords known to the attacker. This process bypasses the registration settings configured on the site.
Recommendations Update the Project Manager WordPress plugin to version 4.0.7 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74928

Affected Products

Project Manager