Impact
The vulnerability is a broken access control flaw in the WP Project Manager plugin, where users with the Subscriber role can access and perform actions that should be restricted to higher‑privileged users. The flaw can allow a Subscriber to view or modify project data, potentially compromising confidentiality and integrity of project information.
Affected Systems
The affected product is the weDevs WP Project Manager plugin for WordPress. Versions up to and including 4.0.7 contain the flaw. Users operating any of these versions are at risk until they update to a fixed release.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity, and the lack of an EPSS score implies no publicly known exploitation data at this time. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to authenticate as a Subscriber or gain access to an account with that role to exploit the issue. Once authenticated, the attacker can bypass the intended role‑based restrictions and gain unauthorized access to project management features.
OpenCVE Enrichment