CyberRota Analysis
AI-GeneratedThe Project Manager WordPress plugin prior to version 4.0.7 is vulnerable due to insufficient restrictions on its REST API routes, enabling authenticated users to access and modify task content and user email addresses from projects they do not belong to. This could lead to unauthorized data exposure and manipulation of project boards. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential risks.
Original NVD Description
The Project Manager WordPress plugin before 4.0.7 does not restrict several of its REST API routes to the projects a user belongs to, allowing any authenticated user, such as a subscriber, to read other projects' task content and user email addresses and to modify other projects' task boards.