Cross-Site Request Forgery Vulnerability in WP Project Manager Plugin by WordPress
CVE-2020-36745

4.3MEDIUM

Summary

The WP Project Manager plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit Cross-Site Request Forgery (CSRF). This issue arises from improper nonce validation within the do_updates() function, allowing attackers to potentially execute unauthorized updates on the WordPress site. Exploitation is possible if a site administrator is tricked into triggering a malicious request, thereby compromising the site's integrity and security.

Affected Version(s)

WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts * < 2.4.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jerome Bruandet
.