A popular project management plugin for WordPress, called WP Project Manager, has a security vulnerability in all versions up to and including 2.6.13. This vulnerability allows hackers to pretend to be an administrator and gain access to all of the plugin’s REST routes. The issue is caused by a lack of validation on a key that is controlled by the user.