WordPress security by component
Progress Planner
Plugin description
Progress Planner is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Jun 02, 2026; the highest CVE/CNA score is 8.8.
Plugin slug:
progress-plannerLatest vulnerability
CVE-2026-28116: Progress Planner: Cross-site scripting
Progress Planner is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.9.0.
| Safe version |
|
||
|---|---|---|---|
| Jun 02, 2026 |
CVE-2026-28116
Progress Planner: Cross-site scripting
Progress Planner is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.9.0.
|
1.9.1 |
CVE5.9
NVDPending
|
| Oct 22, 2025 |
CVE-2025-48082
Progress Planner: Privilege escalation or authentication bypass
Progress Planner is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Nov 01, 2024 |
CVE-2024-37411
Progress Planner: A security weakness
Progress Planner is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jul 22, 2024 |
CVE-2024-37422
Progress Planner: Cross-site scripting
Progress Planner is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD5.4
|