CVE-2026-12877: Unknown Project Management, Bug And Issue Tracking Plugin
Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.
The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is exploitable in the Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0's standard front-end issue-tracker configuration.
Affected products
- Unknown Project Management, Bug And Issue Tracking Plugin: before 5.1.0 (fixed in 5.1.0)
Published 2026-07-24. Last modified 2026-07-24.