Access violation vulnerability in WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts 2.6.14

The WP Project Manager plugin for WordPress has a security issue that allows unauthorized changes to be made to data. This is because certain checks were not included in the ‘check’ method of the ‘Create_Milestone’, ‘Create_Task_List’, ‘Create_Task’, and ‘Delete_Task’ classes in version 2.6.14. This means that people who are not logged in can create milestones, task lists, tasks, or delete tasks in any project. Please note that version 2.6.14 did try to fix this issue, but it was only a partial fix.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.