PT-2026-81959 · WordPress · Project Manager
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Project Manager WordPress plugin versions prior to 4.0.7
Description
An Insecure Direct Object Reference (IDOR) exists where several REST API routes are not restricted to the projects a user belongs to. This allows any authenticated user, including those with subscriber privileges, to read task content and user email addresses from other projects, as well as modify task boards belonging to other projects.
Recommendations
Update Project Manager WordPress plugin to version 4.0.7 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Project Manager