Executive brief
WP Project Manager is a WordPress plugin used to organize projects and tasks within WordPress sites. A flaw in its REST API allows any logged-in user—even one with minimal permissions like a subscriber—to view other users' complete activity histories, including private email addresses, and project details they should not have access to. This enables unauthorized disclosure of sensitive business information and employee email addresses.
Technical details
The vulnerability is an Insecure Direct Object Reference (IDOR) flaw in the WP Project Manager REST API routes `/pm/v2/users/{ID}/user-activities` and `/pm/v2/users/{ID}/tasks`. These endpoints fail to verify that the requesting user is authorized to access the target user's data before returning activity feeds, email addresses, and project information. An authenticated attacker with any role (including subscriber) can substitute an arbitrary user ID and retrieve complete activity logs, email addresses, usernames, roles, and sensitive project details (title, description, budget, completion date) that they should not have permission to view. Exploitation requires only valid WordPress authentication and a nonce; no additional privileges or complex attack steps are needed. The vulnerability affects versions 2.2.0 through 4.0.6 and is fixed in version 4.0.7.
Affected products
- wedevs WP Project Manager 2.2.0 through 4.0.6
Timeline
- 2026-08-24: disclosed: Publicly published on WPScan
- 2026-08-26: patched: Fixed in version 4.0.7
- 2026-08-26: other: CVE-2026-74930 assigned