CVE-2025-58269: WordPress WP Project Manager Plugin <= 2.6.25 - Sensitive Data Exposure Vulnerability
Use of Hard-coded Credentials vulnerability in weDevs WP Project Manager allows Retrieve Embedded Sensitive Data. This issue affects WP Project Manager: from n/a through 2.6.25.
Other sources
Use of Hard-coded Credentials vulnerability in weDevs WP Project Manager wedevs-project-manager allows Retrieve Embedded Sensitive Data.This issue affects WP Project Manager: from n/a through <= 2.6.25.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58269?
CVE-2025-58269 is classified as a critical severity vulnerability due to its ability to expose sensitive embedded data.
How do I fix CVE-2025-58269?
To fix CVE-2025-58269, update the WP Project Manager plugin to the latest version beyond 2.6.25 where the vulnerability is patched.
What versions are affected by CVE-2025-58269?
CVE-2025-58269 affects versions of the WP Project Manager plugin from the earliest version up to and including 2.6.25.
What is the impact of CVE-2025-58269?
The impact of CVE-2025-58269 includes unauthorized access to sensitive data due to hard-coded credentials in the WP Project Manager.
Who is the vendor for the software affected by CVE-2025-58269?
The vendor for the software affected by CVE-2025-58269 is weDevs, known for the WP Project Manager plugin.