First published: Wed Nov 20 2024(Updated: )
The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' method of the 'Create_Milestone', 'Create_Task_List', 'Create_Task', and 'Delete_Task' classes in version 2.6.14. This makes it possible for unauthenticated attackers to create milestones, create task lists, create tasks, or delete tasks in any project. NOTE: Version 2.6.14 implemented a partial fix for this vulnerability.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP Project Manager by WeDevs | <2.6.15 | |
weDevs WP Project Manager | <=2.6.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10520 is classified as a high severity vulnerability due to unauthorized modification of data.
To fix CVE-2024-10520, update the WP Project Manager plugin to version 2.6.15 or later.
CVE-2024-10520 affects WP Project Manager plugin versions up to and including 2.6.14.
CVE-2024-10520 enables unauthorized users to modify data through missing capability checks.
The vendor for CVE-2024-10520 is WeDevs, the creator of the WP Project Manager plugin.