Executive brief
A vulnerability in the Project Management, Bug and Issue Tracking plugin for WordPress allows unauthorized individuals to access or modify your website's database. This plugin is used to manage tasks and track software bugs directly on a website. An attacker could exploit this flaw to steal sensitive customer information, alter site content, or disrupt business operations without needing a password or account.
Technical details
The Software Issue Manager (Project Management, Bug and Issue Tracking) plugin for WordPress fails to properly sanitize and escape user-supplied input in its front-end search functionality. Specifically, when the 'limit by author' setting is enabled (which is a default state), the raw search term provided via the 's' parameter is concatenated directly into a SQL UNION query. An unauthenticated attacker can exploit this by sending crafted web requests to execute arbitrary SQL commands. This can lead to full database compromise, including the extraction of sensitive data or administrative credentials. The issue is fixed in version 5.1.0.
Affected products
- Unknown Project Management, Bug and Issue Tracking Plugin (Software Issue Manager) < 5.1.0
Timeline
- 2026-07-03: disclosed: Initial public disclosure via WPScan
- 2026-07-24: advisory: NVD publication date