SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-74929

MEDIUM · CVSS 5.4 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Project Manager WordPress plugin prior to version 4.0.7 is vulnerable due to insufficient restrictions on its REST API routes, enabling authenticated users to access and modify task content and user email addresses from projects they do not belong to. This could lead to unauthorized data exposure and manipulation of project boards. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential risks.

CVE
CVE-2026-74929
Severity
MEDIUM
CVSS
5.4
EPSS
0.18%
WordPress

Original NVD Description

The Project Manager WordPress plugin before 4.0.7 does not restrict several of its REST API routes to the projects a user belongs to, allowing any authenticated user, such as a subscriber, to read other projects' task content and user email addresses and to modify other projects' task boards.