PT-2026-81960 · WordPress · Project Manager

·

CVE-2026-74930

·

Published

2026-08-26

·

Updated

2026-08-26

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Project Manager versions 2.2.0 through 4.0.6
Description An Insecure Direct Object Reference (IDOR) exists in a REST API route where the plugin fails to verify if the authenticated user requesting activity data is the owner of that data. This allows any authenticated user, including those with subscriber-level privileges, to access the activity history of other users, exposing their email addresses and details of projects they are not authorized to view.
Recommendations Update Project Manager to version 4.0.7 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74930

Affected Products

Project Manager