WordPress security by component
WP Project Manager
Plugin description
WP Project Manager is a WordPress component with 15 published CVE records in this archive. The latest tracked vulnerability was published Dec 30, 2025; the highest CVE/CNA score is 8.8.
Plugin slug:
wedevs-project-managerLatest vulnerability
CVE-2025-68040: WP Project Manager: A security weakness
WP Project Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
| Safe version |
|
||
|---|---|---|---|
| Dec 30, 2025 |
CVE-2025-68040
WP Project Manager: A security weakness
WP Project Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Nov 15, 2025 |
CVE-2025-8994
Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager: SQL injection
Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Sep 22, 2025 |
CVE-2025-58269
WP Project Manager: A security weakness
WP Project Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Apr 11, 2025 |
CVE-2025-2541
WP Project Manager: Cross-site scripting
WP Project Manager is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 09, 2025 |
CVE-2025-3100
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts: Cross-site scripting
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts is affected by cross-site scripting. Exploitation requires at least subscriber-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Feb 15, 2025 |
CVE-2024-13500
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts: SQL injection
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Feb 15, 2025 |
CVE-2024-13752
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts: A security weakness
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jan 04, 2025 |
CVE-2024-12195
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts: SQL injection
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 02, 2024 |
CVE-2024-12015
WP Project Manager: SQL injection
WP Project Manager is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.7
NVDPending
|
| Nov 13, 2024 |
CVE-2024-10174
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts: A security weakness
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.3
NVDPending
|
| Dec 14, 2023 |
CVE-2023-49860
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts: Cross-site scripting
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Nov 03, 2023 |
CVE-2023-34383
WP Project Manager: SQL injection
WP Project Manager is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVD9.8
|
| Aug 31, 2023 |
CVE-2023-3636
WP Project Manager: Privilege escalation or authentication bypass
WP Project Manager is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Jul 01, 2023 |
CVE-2020-36745
WP Project Manager: Cross-site request forgery
WP Project Manager is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Apr 04, 2022 |
CVE-2021-36826
Wedevs Project Manager: Cross-site scripting
Wedevs Project Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|