CVE-2025-22649: WordPress WP Project Manager plugin <= 2.6.22 - Cross Site Scripting (XSS) vulnerability
Published Mar 27, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project Manager wedevs-project-manager allows Stored XSS.This issue affects WP Project Manager: from n/a through <= 2.6.22.
Affected Software
2 affected components
weDevs Wp Project Manager Wordpress<=2.6.22
weDevs WP Project Manager<=2.6.22
Event History
Mar 27, 2025
CVE Published
via MITRE·03:05 PM
Data Sourced
via MITRE·03:05 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 14, 58279
Event
via MITRE·11:26 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-22649?
CVE-2025-22649 is classified as a high severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2025-22649?
To remediate CVE-2025-22649, upgrade the WP Project Manager plugin to version 2.6.23 or later.
3
Who is affected by CVE-2025-22649?
CVE-2025-22649 affects users of WP Project Manager versions up to and including 2.6.22.
4
What type of vulnerability is CVE-2025-22649?
CVE-2025-22649 is a stored cross-site scripting (XSS) vulnerability.
5
What are the risks associated with CVE-2025-22649?
Exploiting CVE-2025-22649 can allow attackers to inject harmful scripts that may compromise user data and session hijacking.