PT-2024-16361 · WordPress · Wp Project Manager

Noah Stead

+1

·

Published

2024-12-19

·

Updated

2025-02-05

·

CVE-2024-10548

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WP Project Manager plugin for WordPress versions prior to 2.6.16
Description The issue allows authenticated attackers with Subscriber-level access and above to extract sensitive data, including hashed passwords of project owners, via the /wp-json/pm/v2/projects/1/task-lists REST API endpoint. This makes it possible for attackers to access confidential information.
Recommendations For WP Project Manager plugin for WordPress versions prior to 2.6.16, update to the latest version to secure your site. As a temporary workaround, consider restricting access to the /wp-json/pm/v2/projects/1/task-lists API endpoint to minimize the risk of exploitation.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-10548

Affected Products

Wp Project Manager