First published: Sat Feb 15 2025(Updated: )
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check in the '/pm/v2/settings/notice' endpoint all versions up to, and including, 2.6.17. This makes it possible for authenticated attackers, with Subscriber-level access and above, to cause a persistent denial of service condition.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP Project Manager | <=2.6.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-13752 is categorized as a high severity vulnerability due to the potential for unauthorized data loss.
To fix CVE-2024-13752, update the WP Project Manager plugin to version 2.6.18 or later.
CVE-2024-13752 affects all versions of WP Project Manager up to and including version 2.6.17.
CVE-2024-13752 is a security vulnerability related to unauthorized data access due to a missing capability check.
The vendor for CVE-2024-13752 is WP Project Manager, responsible for the affected plugin.