Stored Cross-Site Scripting in WP Project Manager Plugin
CVE-2025-2541
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 April 2025
What is CVE-2025-2541?
The WP Project Manager plugin for WordPress is susceptible to a stored cross-site scripting vulnerability. This issue arises from inadequate input sanitization and output escaping during SVG file uploads. Authenticated users with Author-level access and higher can exploit this vulnerability, injecting arbitrary web scripts that execute whenever the SVG file is accessed. It is imperative to update the plugin to the latest version to safeguard against potential threats.
Affected Version(s)
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts * <= 2.6.22