The WordPress Project Manager plugin, versions up to and including 2.6.0, has a vulnerability that could enable someone with a subscriber-level account or higher to access sensitive information from the database. This vulnerability is caused by the way the plugin escapes user input data and by the lack of preparation of existing SQL queries.