Junglewise Threat Intelligence

CVE-2026-32478: WordPress WP Project Manager Pro SQL injection

CVE-2026-32478 · Severity: high · CVSS 8.5 · Published 2026-08-24

Executive brief

WP Project Manager Pro is a WordPress plugin for managing projects and team collaboration. A SQL injection vulnerability in versions up to 4.0.1 allows authenticated subscribers to query, modify, or delete database records, potentially exposing sensitive project data, user credentials, and other private information stored in the database.

Technical details

The vulnerability is a SQL injection flaw requiring subscriber-level authentication to exploit. Attackers with subscriber accounts can inject malicious SQL commands through the plugin's input handling, allowing arbitrary database reads, modifications, and deletions. The affected versions are 4.0.1 and earlier. No official patch has been released as of the advisory publication date (21 Aug 2026); a workaround via third-party mitigation rules was available through Patchstack.

Affected products

  • WeDev WP Project Manager Pro <= 4.0.1

Timeline

  • 2026-08-21: disclosed
  • 2026-08-24: other: NVD publication

References