The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' method of the 'Create_Milestone', 'Create_Task_List', 'Create_Task', and 'Delete_Task' classes in version 2.6.14. This makes it possible for unauthenticated attackers to create milestones, create task lists, create tasks, or delete tasks in any project. NOTE: Version 2.6.14 implemented a partial fix for this vulnerability.
References
Link | Resource |
---|---|
https://plugins.trac.wordpress.org/changeset/3191204/wedevs-project-manager | Broken Link |
https://www.wordfence.com/threat-intel/vulnerabilities/id/497760a8-7d4a-45a0-91e4-a8ee27bcdb02?source=cve | Third Party Advisory |
Configurations
History
05 Feb 2025, 16:51
Type | Values Removed | Values Added |
---|---|---|
References | () https://plugins.trac.wordpress.org/changeset/3191204/wedevs-project-manager - Broken Link | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/497760a8-7d4a-45a0-91e4-a8ee27bcdb02?source=cve - Third Party Advisory | |
First Time |
Wedevs
Wedevs wp Project Manager |
|
CPE | cpe:2.3:a:wedevs:wp_project_manager:*:*:*:*:*:wordpress:*:* |
21 Nov 2024, 13:57
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
20 Nov 2024, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-20 12:15
Updated : 2025-02-05 16:51
NVD link : CVE-2024-10520
Mitre link : CVE-2024-10520
CVE.ORG link : CVE-2024-10520
JSON object : View
Products Affected
wedevs
- wp_project_manager
CWE
CWE-862
Missing Authorization