CVE-2025-3100: WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.22 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22 due to insufficient input sanitization and output escaping in tasks discussion. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions granted by an Administrator, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3100?
CVE-2025-3100 has a severity rating due to its potential to allow Stored Cross-Site Scripting attacks.
How do I fix CVE-2025-3100?
To fix CVE-2025-3100, update the WP Project Manager plugin to version 2.6.23 or later where the vulnerability is addressed.
Which versions of WP Project Manager are affected by CVE-2025-3100?
CVE-2025-3100 affects all versions of WP Project Manager up to and including version 2.6.22.
What types of attacks can CVE-2025-3100 facilitate?
CVE-2025-3100 can facilitate Stored Cross-Site Scripting attacks through insecure handling of SVG file uploads.
Is user input properly sanitized in CVE-2025-3100?
No, CVE-2025-3100 is caused by insufficient input sanitization of SVG file uploads.