CVE-2025-32280: WordPress WP Project Manager plugin < 2.6.25 - Cross Site Request Forgery (CSRF) Vulnerability
Published Apr 4, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in weDevs WP Project Manager wedevs-project-manager allows Cross Site Request Forgery.This issue affects WP Project Manager: from n/a through < 2.6.25.
Affected Software
2 affected components
weDevs Wp Project Manager Wordpress<=2.6.22
weDevs WP Project Manager<=2.6.22
Event History
Apr 4, 2025
CVE Published
via MITRE·03:59 PM
Data Sourced
via MITRE·03:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-32280?
CVE-2025-32280 is classified as a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2025-32280?
To fix CVE-2025-32280, update the WP Project Manager plugin to the latest version beyond 2.6.22.
3
What software is affected by CVE-2025-32280?
CVE-2025-32280 affects the weDevs WP Project Manager plugin versions up to and including 2.6.22.
4
What type of attack is CVE-2025-32280 associated with?
CVE-2025-32280 is associated with a Cross-Site Request Forgery (CSRF) attack which allows unauthorized actions on behalf of users.
5
Can CVE-2025-32280 be exploited remotely?
Yes, CVE-2025-32280 can be exploited remotely by attackers if a user is tricked into making a request.