CVE-2026-97281: WordPress WP Project Manager plugin <= 4.0.7 - Broken Access Control vulnerability
Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Project Manager pluginto a version that resolves this vulnerability.Fixed in 4.1.0
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that an attacker needs low-level privileges. The vulnerability is described as involving subscriber access control, so a subscriber-level account is relevant to exploitation.
Does exploitation require user interaction or local access?
No user interaction is required, and the attack vector is network-based. An attacker with the required low privileges can attempt exploitation remotely.
What is the likely security impact if exploited?
The CVSS vector rates confidentiality, integrity, and availability impacts as low. Exploitation may therefore cause limited unauthorized disclosure, modification, or service impact.