Executive brief
WP Project Manager Pro is a popular WordPress plugin used by thousands of websites to manage projects, tasks, and team collaboration within WordPress. The plugin contains a SQL injection vulnerability that allows authenticated users with basic subscriber-level access to extract sensitive data from the website's database, potentially exposing client information, project details, or other confidential records.
Technical details
The vulnerability is a SQL injection (SQLi) flaw caused by insufficient escaping of user-supplied parameters and inadequate preparation of SQL queries. Authenticated attackers with Subscriber-level access or above can inject malicious SQL code into database queries to extract sensitive information. The vulnerability affects all versions up to and including 4.0.1. Attack preconditions require an attacker to have authenticated access to the WordPress site (minimum Subscriber role). No patch availability is mentioned in the advisory.
Affected products
- weDevs WP Project Manager Pro up to and including 4.0.1
Timeline
- 2026-08-25: disclosed