SQL Injection Vulnerability in WP Project Manager Pro Plugin for WordPress
CVE-2026-78470
6.5MEDIUM
What is CVE-2026-78470?
The WP Project Manager Pro plugin for WordPress has a SQL Injection vulnerability due to inadequate input handling and escaping. This affects all versions up to and including 4.0.1. Authenticated attackers with Subscriber-level access or higher can exploit this flaw to inject additional SQL queries into existing database queries. Such actions may allow attackers to extract sensitive information from the database, compromising the security and confidentiality of the data managed through the plugin.
Affected Version(s)
WP Project Manager Pro 0 <= 4.0.1