Projectopia – WordPress Project Management <= 5.1.19 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion
CVE-2025-12876
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 December 2025
What is CVE-2025-12876?
The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pto_delete_file AJAX action in all versions up to, and including, 5.1.19. This makes it possible for unauthenticated attackers to delete arbitrary attachments.
Affected Version(s)
Projectopia – WordPress Project Management * <= 5.1.19