CVE-2024-10548
WP Project Manager <= 2.6.15 - Authenticated (Subscriber+) Sensitive Information Exposure via Project Task List REST API
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.15 via the Project Task List ('/wp-json/pm/v2/projects/1/task-lists') REST API endpoint. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive data including the hashed passwords of project owners (e.g. adminstrators).
El complemento WP Project Manager para WordPress es vulnerable a la exposición de información confidencial en todas las versiones hasta la 2.6.15 incluida a través del endpoint de la API REST de la lista de tareas del proyecto ('/wp-json/pm/v2/projects/1/task-lists'). Esto permite que atacantes autenticados, con acceso de nivel de suscriptor y superior, extraigan datos confidenciales, incluidas las contraseñas cifradas de los propietarios del proyecto (por ejemplo, los administradores).
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-10-30 CVE Reserved
- 2024-12-18 CVE Published
- 2024-12-19 EPSS Updated
- 2024-12-20 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (2)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wedevs Search vendor "Wedevs" | WP Project Manager – Task, Team, And Project Management Plugin Featuring Kanban Board And Gantt Charts Search vendor "Wedevs" for product "WP Project Manager – Task, Team, And Project Management Plugin Featuring Kanban Board And Gantt Charts" | <= 2.6.15 Search vendor "Wedevs" for product "WP Project Manager – Task, Team, And Project Management Plugin Featuring Kanban Board And Gantt Charts" and version " <= 2.6.15" | en |
Affected
|