Wp Project Manager
Vendor:
First CVE: Apr 4, 2022 · Active for 4 years
18
Total CVEs
More Total CVEs than 93% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Wp Project Manager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 4, 2022
4 years ago
Most Recent CVE
Dec 30, 2025
209 days ago
CVE Severity & Scoring
Wp Project Manager18 CVEs
67%
22%
11%
All CVEs352,727 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (61.1%)
Unknown0 (0.0%)
Required7 (38.9%)
Privileges Required
Low10 (55.6%)
High1 (5.6%)
None7 (38.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-40003CRITICAL Missing Authorization vulnerability in weDevs WP Project Manager wedevs-project-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects W | Dec 13, 2024 | 9.8 | 25 | NO | NO |
CVE-2020-36745HIGH The WP Project Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.0. This is due to missing or incorrect nonce validatio | Jul 1, 2023 | 8.8 | 25 | NO | NO |
CVE-2025-32280HIGH Cross-Site Request Forgery (CSRF) vulnerability in weDevs WP Project Manager wedevs-project-manager allows Cross Site Request Forgery.This issue affects WP Project Manager: from n/ | Apr 4, 2025 | 8.8 | 24 | NO | NO |
CVE-2023-34383CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP Project Manager wedevs-project-manager allows SQL Injection.This iss | Nov 3, 2023 | 9.8 | 24 | NO | NO |
CVE-2024-10174HIGH The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Insecure Direct Object Reference in | Nov 13, 2024 | 7.3 | 22 | NO | NO |
CVE-2023-3636HIGH The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.4 due to insufficient restriction on the 'save_users_map_nam | Aug 31, 2023 | 8.8 | 22 | NO | NO |
CVE-2025-68040MEDIUM Insertion of Sensitive Information Into Sent Data vulnerability in weDevs WP Project Manager wedevs-project-manager allows Retrieve Embedded Sensitive Data.This issue affects WP Pr | Dec 30, 2025 | 6.5 | 20 | NO | NO |
CVE-2024-10548MEDIUM The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.15 via the Project Task List ('/wp-json/pm/v2/ | Dec 19, 2024 | 6.5 | 20 | NO | NO |
CVE-2021-36826MEDIUM Authenticated (subscriber or higher user role if allowed to access projects) Stored Cross-Site Scripting (XSS) vulnerability in weDevs WP Project Manager plugin <= 2.4.13 versions. | Apr 4, 2022 | 5.4 | 20 | NO | NO |
CVE-2025-58269MEDIUM Use of Hard-coded Credentials vulnerability in weDevs WP Project Manager wedevs-project-manager allows Retrieve Embedded Sensitive Data.This issue affects WP Project Manager: from | Sep 22, 2025 | 5.3 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Wp Project Manager
Top CWEs
Versions
No cataloged versions.