WordPress Plugin Vulnerabilities

WP Project Manager < 2.6.15 - Missing Authorization to Project Milestone and Task Creation/Deletion

Description

The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' method of the 'Create_Milestone', 'Create_Task_List', 'Create_Task', and 'Delete_Task' classes in version 2.6.14. This makes it possible for unauthenticated attackers to create milestones, create task lists, create tasks, or delete tasks in any project. NOTE: Version 2.6.14 implemented a partial fix for this vulnerability.

Affects Plugins

Fixed in 2.6.15

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Noah Stead (TurtleBurg)
Verified
No

Timeline

Publicly Published
2024-11-19 (about 1 year ago)
Added
2024-11-19 (about 1 year ago)
Last Updated
2024-11-20 (about 1 year ago)

Other