CVE-2024-12015: Wedevs Wp Project Manager

High severity, CVSS 7.7. EPSS: 0.5% chance of exploitation in the next 30 days.

The 'Project Manager' WordPress Plugin is affected by an authenticated SQL injection vulnerability in the 'orderby' parameter in the '/pm/v2/activites' route.

Affected products

  • Wedevs Wp Project Manager: version 0 only; any version

Published 2024-12-02. Last modified 2026-06-17.