The WP Project Manager plugin for WordPress has a security vulnerability in versions up to and including 2.6.7. This means that attackers with a subscriber-level access or higher can inject malicious web scripts into pages. When a user visits an injected page, the malicious web scripts will run. This vulnerability is caused by not properly sanitizing and escaping inputs.