First published: Mon Oct 11 2021(Updated: )
Authenticated (subscriber or higher user role if allowed to access projects) Stored Cross-Site Scripting (XSS) vulnerability in weDevs WP Project Manager plugin <= 2.4.13 versions.
Credit: audit@patchstack.com audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wedevs Wp Project Manager | <2.4.14 |
Update to 2.4.14 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-36826 is medium with a severity value of 5.4.
CVE-2021-36826 affects weDevs WP Project Manager plugin versions up to and including 2.4.13.
The CWE ID for CVE-2021-36826 is 79.
Yes, authentication is required to exploit CVE-2021-36826.
Yes, there is a patch available for CVE-2021-36826. Please refer to the reference link for more information.