CVE-2024-10520

Publication date

2024-11-20 11:33:10

Family

Wordfence

State

PUBLISHED

Description

The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the check method of the Create_Milestone, Create_Task_List, Create_Task, and Delete_Task classes in version 2.6.14. This makes it possible for unauthenticated attackers to create milestones, create task lists, create tasks, or delete tasks in any project. NOTE: Version 2.6.14 implemented a partial fix for this vulnerability.