CVE-2026-74928
WP Project Manager 2.1.0 - 4.0.6 - Unauthenticated Subscriber Account Creation via Trello Import Routes
CVSS Score
7.5
EPSS Score
0.2%
EPSS Percentile
7th
The Project Manager WordPress plugin before 4.0.7 does not have any authorisation check on its import routes, allowing unauthenticated users to create WordPress accounts with a password the attacker already knows, bypassing the site's own registration setting.
| Vendor | unknown |
| Product | project manager |
| Published | Aug 26, 2026 |
| Last Updated | Aug 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown project manager
Be the first to know when new high vulnerabilities affecting unknown project manager are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Project Manager
2.1.0 < 4.0.7
References
Credits
Usama Arshad WPScan