CVE-2025-68040: WordPress WP Project Manager plugin <= 3.0.1 - Sensitive Data Exposure vulnerability
Insertion of Sensitive Information Into Sent Data vulnerability in weDevs WP Project Manager wedevs-project-manager allows Retrieve Embedded Sensitive Data.This issue affects WP Project Manager: from n/a through <= 3.0.1.
Other sources
Insertion of Sensitive Information Into Sent Data vulnerability in weDevs WP Project Manager wedevs-project-manager allows Retrieve Embedded Sensitive Data.This issue affects WP Project Manager: from n/a through 3.0.1.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68040?
CVE-2025-68040 is classified as a medium severity vulnerability.
How do I fix CVE-2025-68040?
To fix CVE-2025-68040, update your weDevs WP Project Manager to version 3.0.2 or later.
What kind of data is exposed in CVE-2025-68040?
CVE-2025-68040 exposes sensitive information that may be embedded in sent data.
Which versions of weDevs WP Project Manager are affected by CVE-2025-68040?
CVE-2025-68040 affects weDevs WP Project Manager versions up to and including 3.0.1.
Is there a known attack vector for CVE-2025-68040?
Yes, attackers can exploit this vulnerability to retrieve embedded sensitive data from the affected plugin.