PT-2025-18358 · WordPress · Projectopia
Cheng Liu
·
Published
2025-05-01
·
Updated
2025-05-19
·
CVE-2025-3952
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The Projectopia – WordPress Project Management plugin for WordPress versions up to, and including, 5.1.16
Description
The issue allows unauthorized modification of data, potentially leading to a denial of service. This is due to a missing capability check on the
pto remove logo function. Authenticated attackers with Subscriber-level access and above can delete arbitrary option values on the WordPress site, which can be leveraged to create an error and deny service to legitimate users.Recommendations
For versions up to, and including, 5.1.16, update to a version higher than 5.1.16 to resolve the issue.
As a temporary workaround, consider restricting access to the
pto remove logo function until a patch is available.Fix
DoS
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Projectopia