WP Project Manager <= 2.6.26 - Authenticated (Subscriber+) SQL Injection via 'completed_at_operator'
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker
Minimum safe version
3.0.2
Update to 3.0.2 or later to address 25 fixable vulnerabilities
WP Project Manager <= 2.6.25 - Unauthenticated Sensitive Information Exposure
CVE-2025-68040
WP Project Manager <= 2.6.22 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.22 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload
CVE-2025-32280
CVE-2025-22649
CVE-2024-13752
CVE-2024-13500
CVE-2024-12195
CVE-2024-10548
WordPress WP Project Manager Plugin <= 2.6.16 is vulnerable to SQL Injection
CVE-2024-10520
CVE-2024-10174
CVE-2023-40003
CVE-2023-49860
CVE-2023-34383
WordPress WP Project Manager Plugin <= 2.6.0 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2023-3636
CVE-2020-36745
CVE-2021-4342
Various Affected Software (Various Versions) - Cross-Site Request Forgery Bypass
WordPress WP Project Manager plugin <= 2.4.0 - Cross-Site Request Forgery (CSRF) vulnerability
WordPress WP Project Manager plugin <= 2.4.9 - Cross-Site Request Forgery (CSRF) vulnerability
CVE-2021-36826