The WP Project Manager plugin for WordPress has a security issue that allows hackers to access sensitive information. This can happen through the Project Task List feature, which is part of the ‘/wp-json/pm/v2/projects/1/task-lists’ REST API endpoint. This means that attackers who have logged in with at least Subscriber-level access can see confidential information, such as the hashed passwords of project owners (like administrators).