cleantalk
Vulnerabilities and Security Researches

WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts, CVE-2024-12015

CVE, Research URL

CVE-2024-12015

Published on
Dec 02, 2024
Research Description
The 'Project Manager' WordPress Plugin is affected by an authenticated SQL injection vulnerability in the 'orderby' parameter in the '/pm/v2/activites' route.
Affected versions
Min -, max 2.6.14.
Status
vulnerable