Executive brief
Projectopia, a project management plugin for WordPress, contains a security flaw that could allow unauthorized individuals to access sensitive information. By exploiting this vulnerability, an attacker can view data they are not permitted to see, potentially compromising client details or project information. This issue affects all versions up to and including 5.1.25.2, and no official patch has been released yet.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the Projectopia plugin for WordPress (versions <= 5.1.25.2) due to insufficient authorization checks on custom roles. The flaw, classified as CWE-639, allows a remote attacker to bypass intended access restrictions by manipulating input identifiers to access objects or data belonging to other users. According to the CVSS vector, the attack can be carried out over the network without authentication or user interaction, leading to high confidentiality impact. As of the advisory date, no official patch is available, and users are advised to monitor for updates from the developer.
Affected products
- Projectopia Projectopia <= 5.1.25.2
Timeline
- 2025-11-02: other: Reported by researcher 0xVenus
- 2025-12-02: advisory: Initial disclosure by Patchstack
- 2026-06-15: disclosed: NVD publication date