Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-74929

MEDIUM NVD
CVSS Score 5.4
Severity MEDIUM
Published Aug 26, 2026
Vendor unknown

Description

The Project Manager WordPress plugin before 4.0.7 does not restrict several of its REST API routes to the projects a user belongs to, allowing any authenticated user, such as a subscriber, to read other projects' task content and user email addresses and to modify other projects' task boards.

References