Beveiligingsadvies

CVE-2026-74929

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-26 06:00:20
Laatst bijgewerkt 2026-08-26 14:43:08
Toegewezen door WPScan
CVSS-score 5.4
Status PUBLISHED

Beschrijving

The Project Manager WordPress plugin before 4.0.7 does not restrict several of its REST API routes to the projects a user belongs to, allowing any authenticated user, such as a subscriber, to read other projects' task content and user email addresses and to modify other projects' task boards.