The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' method of the 'Create_Milestone', 'Create_Task_List', 'Create_Task', and 'Delete_Task' classes in version 2.6.14. This makes it possible for unauthenticated attackers to create milestones, create task lists, create tasks, or delete tasks in any project. NOTE: Version 2.6.14 implemented a partial fix for this vulnerability.

Project Subscriptions

Vendors Products
Wp Project Manager Subscribe
Wp Project Manager Task Team And Project Management Plugin Featuring Kanban Board And Gantt Charts Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2024-33429 The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' method of the 'Create_Milestone', 'Create_Task_List', 'Create_Task', and 'Delete_Task' classes in version 2.6.14. This makes it possible for unauthenticated attackers to create milestones, create task lists, create tasks, or delete tasks in any project. NOTE: Version 2.6.14 implemented a partial fix for this vulnerability.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 05 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Wedevs wp Project Manager
CPEs cpe:2.3:a:wedevs:wp_project_manager:*:*:*:*:*:wordpress:*:*
Vendors & Products Wedevs wp Project Manager

Wed, 20 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Wedevs
Wedevs wp Project Manager Task Team And Project Management Plugin Featuring Kanban Board And Gantt Charts
CPEs cpe:2.3:a:wedevs:wp_project_manager_task_team_and_project_management_plugin_featuring_kanban_board_and_gantt_charts:*:*:*:*:*:*:*:*
Vendors & Products Wedevs
Wedevs wp Project Manager Task Team And Project Management Plugin Featuring Kanban Board And Gantt Charts
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 20 Nov 2024 11:45:00 +0000

Type Values Removed Values Added
Description The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' method of the 'Create_Milestone', 'Create_Task_List', 'Create_Task', and 'Delete_Task' classes in version 2.6.14. This makes it possible for unauthenticated attackers to create milestones, create task lists, create tasks, or delete tasks in any project. NOTE: Version 2.6.14 implemented a partial fix for this vulnerability.
Title WP Project Manager <= 2.6.14 - Missing Authorization to Project Milestone and Task Creation/Deletion
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-11-20T15:14:12.419Z

Reserved: 2024-10-29T23:15:27.952Z

Link: CVE-2024-10520

cve-icon Vulnrichment

Updated: 2024-11-20T15:13:27.196Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-20T12:15:18.390

Modified: 2025-02-05T16:51:57.997

Link: CVE-2024-10520

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses