medium · CVSS v3 6.3
CVE-2026-97281
CVE-2026-97281 is a broken access control issue affecting the WP Project Manager WordPress plugin in versions 4.0.7 and earlier. The flaw ma
Overview
CVE-2026-97281 is a broken access control issue affecting the WP Project Manager WordPress plugin in versions 4.0.7 and earlier. The flaw may allow users with the Subscriber role to access data or functionality they should not be able to reach. It matters because WordPress sites using this plugin may expose project, task, or user information to low-privileged accounts.
Description
Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions.
Impact
The primary impact is confidentiality, with possible integrity effects if subscribers can modify or view restricted project data. Availability is less likely to be directly affected. Impacted parties include WordPress site operators, project managers, clients, and users whose project information is stored in the plugin. The risk is elevated on sites where Subscriber accounts have access to sensitive business or client data.
Remediation
Update WP Project Manager to a version later than 4.0.7 as soon as a vendor fix is available. Review and restrict Subscriber role permissions to only the capabilities required for normal use. Audit existing user accounts and remove or demote unnecessary Subscriber accounts. Enable WordPress and plugin logging, and monitor access patterns for unusual Subscriber activity. Apply a web application firewall or access-control rules to limit exposure of plugin endpoints if immediate patching is not possible.
Risk context
The issue is rated medium severity with a CVSS v3 score of 6.3, and no EPSS score is provided. Defenders should treat it as a moderate-priority patch, especially on production WordPress sites with active Subscriber accounts or sensitive project data.
Affected products
- WP Project Manager <= 4.0.7
- WordPress
Scores
- Severity
- medium
- CVSS v2
- 6.5
- CVSS v3
- 6.3
- CVSS v4
- —
- EPSS
- —