CVE-2026-74929: Unknown Project Manager

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

The Project Manager WordPress plugin before 4.0.7 does not restrict several of its REST API routes to the projects a user belongs to, allowing any authenticated user, such as a subscriber, to read other projects' task content and user email addresses and to modify other projects' task boards.

Affected products

  • Unknown Project Manager: before 4.0.7 (fixed in 4.0.7)

Published 2026-08-26. Last modified 2026-08-26.