VYPR
Medium severity6.5NVD Advisory· Published Feb 15, 2025· Updated Jun 17, 2026

CVE-2024-13752

CVE-2024-13752

Description

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check in the '/pm/v2/settings/notice' endpoint all versions up to, and including, 2.6.17. This makes it possible for authenticated attackers, with Subscriber-level access and above, to cause a persistent denial of service condition.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:wedevs:wp_project_manager:*:*:*:*:*:wordpress:*:*
    Range: <2.6.18
  • WordPress/Wp Project Managerllm-fuzzy2 versions
    <=2.6.17+ 1 more
    • (no CPE)range: <=2.6.17
    • (no CPE)
  • wedevs/Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Trackerv5
    Range: 0

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.