PT-2026-81960 · WordPress · Project Manager
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Project Manager versions 2.2.0 through 4.0.6
Description
An Insecure Direct Object Reference (IDOR) exists in a REST API route where the plugin fails to verify if the authenticated user requesting activity data is the owner of that data. This allows any authenticated user, including those with subscriber-level privileges, to access the activity history of other users, exposing their email addresses and details of projects they are not authorized to view.
Recommendations
Update Project Manager to version 4.0.7 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Project Manager