CVE-2026-74929
WP Project Manager < 4.0.7 - Subscriber+ Cross-Project Task Disclosure and Task Board Modification via IDOR
CVSS Score
5.4
EPSS Score
0.2%
EPSS Percentile
5th
The Project Manager WordPress plugin before 4.0.7 does not restrict several of its REST API routes to the projects a user belongs to, allowing any authenticated user, such as a subscriber, to read other projects' task content and user email addresses and to modify other projects' task boards.
| Vendor | unknown |
| Product | project manager |
| Published | Aug 26, 2026 |
| Last Updated | Aug 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown project manager
Be the first to know when new medium vulnerabilities affecting unknown project manager are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Project Manager
0 < 4.0.7
References
Credits
Pedro Pinho WPScan