CVE-2024-13752: WP Project Manager <= 2.6.17 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check in the '/pm/v2/settings/notice' endpoint all versions up to, and including, 2.6.17. This makes it possible for authenticated attackers, with Subscriber-level access and above, to cause a persistent denial of service condition.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13752?
CVE-2024-13752 is categorized as a high severity vulnerability due to the potential for unauthorized data loss.
How do I fix CVE-2024-13752?
To fix CVE-2024-13752, update the WP Project Manager plugin to version 2.6.18 or later.
What versions are affected by CVE-2024-13752?
CVE-2024-13752 affects all versions of WP Project Manager up to and including version 2.6.17.
What kind of vulnerability is CVE-2024-13752?
CVE-2024-13752 is a security vulnerability related to unauthorized data access due to a missing capability check.
Who is the vendor for CVE-2024-13752?
The vendor for CVE-2024-13752 is WP Project Manager, responsible for the affected plugin.