CVE-2025-12876: Projectopia – Project Management Tool

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pto_delete_file AJAX action in all versions up to, and including, 5.1.19. This makes it possible for unauthenticated attackers to delete arbitrary attachments.

Affected products

  • Projectopia Projectopia – Project Management Tool: up to and including 5.1.19

Published 2025-12-05. Last modified 2026-09-25.