CVE-2026-32478: WordPress WP Project Manager Pro plugin <= 4.0.1 - SQL Injection vulnerability
Published Aug 24, 2026
·Updated
Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.
Affected Software
1 affected component
wordpress/WP Project Manager Pro<=4.0.1
Event History
Aug 24, 2026
CVE Published
via MITRE·11:54 AM
Data Sourced
via MITRE·11:54 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is described as a subscriber SQL injection, and the CVSS vector indicates that low-level privileges are required. An attacker must have an authenticated account with at least subscriber-level access.
2
Can this be exploited remotely without user interaction?
Yes. The CVSS vector identifies network attack access, low attack complexity, and no user interaction requirement. Exploitation still requires low-level authenticated privileges.
3
What security impact could successful exploitation have?
The CVSS vector indicates high confidentiality impact, no integrity impact, and low availability impact. The scope is changed, meaning the vulnerable component could affect resources beyond its own security authority.