Description
Incorrect Privilege Assignment vulnerability in Projectopia Projectopia projectopia-core allows Privilege Escalation.This issue affects Projectopia: from n/a through <= 5.1.24.
Published: 2025-04-17
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Projectopia Core version 5.1.24 and earlier contain an incorrect privilege assignment flaw that allows a legitimate user to gain elevated capabilities beyond those they should possess. The vulnerability arises from the plugin’s failure to correctly enforce role permissions, leading to a privilege escalation scenario that could let an attacker assume the rights of an administrator or other high‑privilege users. This flaw could therefore be used to modify site configuration, access sensitive information, or compromise the entire WordPress installation.

Affected Systems

All WordPress installations that have the Projectopia Core plugin at any version equal to or lower than 5.1.24 are potentially affected. The plugin, often marketed simply as Projectopia or Projectopia Core, is typically used for project management features and is integrated into the WordPress admin dashboard. No specific operating systems or hardware prerequisites are listed, so the issue applies to any environment running a vulnerable plugin version.

Risk and Exploitability

The CVSS score of 9.8 ranks this flaw as critical, and although its EPSS score is < 1 % indicating a low overall probability of exploitation, the weakness remains actively exposed in the wild. Attackers with ordinary authenticated access to the vulnerable plugin—such as users with an unprivileged role—can manipulate the permission linting and elevate themselves to an administrator without any additional credentials. Because the vulnerability is not yet listed in the CISA KEV catalog, it is not known to have been exploited in known incidents, but the high severity implies that site operators should act swiftly. The vulnerability can be exploited by sending crafted requests to functions that perform privilege checks, bypassing role restrictions to perform administrative operations.

Generated by OpenCVE AI on April 30, 2026 at 22:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Projectopia Core to the latest patched release (≥ 5.1.25) as soon as it becomes available.
  • If an update cannot be applied immediately, disable or remove the Projectopia Core plugin to prevent exploitation until a fix is installed.
  • Review and enforce the proper capability definitions for all WordPress roles, ensuring that no user receives administrative privileges unless explicitly intended; consider using a role‑management plugin or custom role configuration to apply the principle of least privilege.

Generated by OpenCVE AI on April 30, 2026 at 22:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11721 Incorrect Privilege Assignment vulnerability in Projectopia Projectopia allows Privilege Escalation. This issue affects Projectopia: from n/a through 5.1.16.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Incorrect Privilege Assignment vulnerability in Projectopia Projectopia allows Privilege Escalation. This issue affects Projectopia: from n/a through 5.1.16. Incorrect Privilege Assignment vulnerability in Projectopia Projectopia projectopia-core allows Privilege Escalation.This issue affects Projectopia: from n/a through <= 5.1.24.
Title WordPress Projectopia - Project Magement Plugin <= 5.1.16 - Privilege Escalation vulnerability WordPress Projectopia plugin <= 5.1.24 - Privilege Escalation vulnerability
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description Incorrect Privilege Assignment vulnerability in Projectopia Projectopia allows Privilege Escalation. This issue affects Projectopia: from n/a through 5.1.16.
Title WordPress Projectopia - Project Magement Plugin <= 5.1.16 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Projectopia Projectopia
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:26.394Z

Reserved: 2025-04-09T11:21:04.030Z

Link: CVE-2025-32648

cve-icon Vulnrichment

Updated: 2025-04-17T17:42:39.475Z

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:48.903

Modified: 2026-04-23T15:29:16.727

Link: CVE-2025-32648

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T22:15:16Z

Weaknesses