Stored Cross-Site Scripting in WP Project Manager Plugin
CVE-2025-2541

5.4MEDIUM

What is CVE-2025-2541?

The WP Project Manager plugin for WordPress is susceptible to a stored cross-site scripting vulnerability. This issue arises from inadequate input sanitization and output escaping during SVG file uploads. Authenticated users with Author-level access and higher can exploit this vulnerability, injecting arbitrary web scripts that execute whenever the SVG file is accessed. It is imperative to update the plugin to the latest version to safeguard against potential threats.

Affected Version(s)

WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts * <= 2.6.22

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Avraham Shemesh
.