The WP Project Manager is a plugin for WordPress that helps manage tasks, teams, and projects. However, it has a vulnerability that allows attackers to inject malicious code into the plugin. This can be done through a parameter called ‘orderby’ and can potentially give attackers access to sensitive information from the database. This vulnerability affects all versions up to 2.6.17.