The WP Project Manager plugin for WordPress has a security vulnerability in versions 2.6.4 and earlier. Attackers with minimal permissions, like a subscriber, can use the ‘save_users_map_name’ function to change their user role by providing the ‘usernames’ parameter. This makes it possible for them to gain more privileges than they should have.