CVE-2026-32478

8.5

weDevs · WP Project Manager Pro

A SQL injection vulnerability in the WP Project Manager Pro plugin allows authenticated subscribers to execute unauthorized database queries.

Executive summary

An authenticated SQL injection vulnerability in the WP Project Manager Pro plugin poses a significant risk of unauthorized database information disclosure.

Vulnerability

This is a SQL injection vulnerability (CWE-89) arising from improper neutralization of user-supplied input. The vulnerability is accessible to authenticated users with subscriber-level privileges, who can leverage the flaw to extract sensitive information from the underlying database.

Business impact

The ability for an authenticated user to perform SQL injection attacks presents a severe threat to data confidentiality. Attackers could potentially bypass application logic to access proprietary project data or sensitive user information. Given the CVSS score of 8.5, this is considered a high-severity issue that requires immediate attention to prevent unauthorized data exposure.

Remediation

Immediate Action: Update the WP Project Manager Pro plugin to a version beyond 4.0.1 immediately.

Proactive Monitoring: Monitor database query logs for anomalous patterns or unauthorized access attempts originating from subscriber-level accounts.

Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets to detect and block common SQL injection patterns targeting the plugin.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability represents a critical security gap that must be addressed promptly. Organizations should verify their current plugin version and apply the vendor-provided security update as soon as it is available to ensure the integrity and confidentiality of their project management data.

More weDevs CVEs