Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

Vulnerabilities 25Slug wedevs-project-managerLatest version 4.0.0WordPress.org →

Minimum safe version

3.0.2

Update to 3.0.2 or later to address 25 fixable vulnerabilities

Latest available4.0.0
Medium 6.5
2025-11-15< 2.6.27

WP Project Manager <= 2.6.26 - Authenticated (Subscriber+) SQL Injection via 'completed_at_operator'

Medium 5.3
2025-09-22< 2.6.26

WP Project Manager <= 2.6.25 - Unauthenticated Sensitive Information Exposure

Medium 6.4
2025-04-11< 2.6.23

WP Project Manager <= 2.6.22 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

Medium 5.4
2025-04-08< 2.6.23

WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.22 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload

High 7.7
2024-12-03< 2.6.14

WordPress WP Project Manager Plugin <= 2.6.16 is vulnerable to SQL Injection

N/A
2023-09-04< 2.6.1

WordPress WP Project Manager Plugin <= 2.6.0 is vulnerable to Cross Site Request Forgery (CSRF)

N/A
2023-06-07< 2.4.10

CVE-2021-4342

N/A
< 2.4.10

Various Affected Software (Various Versions) - Cross-Site Request Forgery Bypass

N/A
2020-09-16< 2.4.1

WordPress WP Project Manager plugin <= 2.4.0 - Cross-Site Request Forgery (CSRF) vulnerability

N/A
2021-03-01< 2.4.10

WordPress WP Project Manager plugin <= 2.4.9 - Cross-Site Request Forgery (CSRF) vulnerability