Vulnerability Description
The Project Manager WordPress plugin before 4.0.7 does not restrict several of its REST API routes to the projects a user belongs to, allowing any authenticated user, such as a subscriber, to read other projects' task content and user email addresses and to modify other projects' task boards.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-74929?
CVE-2026-74929 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The Project Manager WordPress plugin before 4.0.7 does not restrict several of its REST API routes to the projects a user belongs to, allowing any authenticated user, such as a subscriber, to read ot...
How severe is CVE-2026-74929?
CVE-2026-74929 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-74929?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.