rootpwn

medium · CVSS v3 6.3

CVE-2026-97281

CVE-2026-97281 is a broken access control issue affecting the WP Project Manager WordPress plugin in versions 4.0.7 and earlier. The flaw ma

Overview

CVE-2026-97281 is a broken access control issue affecting the WP Project Manager WordPress plugin in versions 4.0.7 and earlier. The flaw may allow users with the Subscriber role to access data or functionality they should not be able to reach. It matters because WordPress sites using this plugin may expose project, task, or user information to low-privileged accounts.

Description

Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions.

Impact

The primary impact is confidentiality, with possible integrity effects if subscribers can modify or view restricted project data. Availability is less likely to be directly affected. Impacted parties include WordPress site operators, project managers, clients, and users whose project information is stored in the plugin. The risk is elevated on sites where Subscriber accounts have access to sensitive business or client data.

Remediation

Update WP Project Manager to a version later than 4.0.7 as soon as a vendor fix is available. Review and restrict Subscriber role permissions to only the capabilities required for normal use. Audit existing user accounts and remove or demote unnecessary Subscriber accounts. Enable WordPress and plugin logging, and monitor access patterns for unusual Subscriber activity. Apply a web application firewall or access-control rules to limit exposure of plugin endpoints if immediate patching is not possible.

Risk context

The issue is rated medium severity with a CVSS v3 score of 6.3, and no EPSS score is provided. Defenders should treat it as a moderate-priority patch, especially on production WordPress sites with active Subscriber accounts or sensitive project data.

Affected products

  • WP Project Manager <= 4.0.7
  • WordPress

Scores

Severity
medium
CVSS v2
6.5
CVSS v3
6.3
CVSS v4
—
EPSS
—

wordpress wp-project-manager broken-access-control subscriber-role privilege-escalation-risk patch-management

← All CVEs