Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-12877: WordPress Project Management Plugin SQL Injection Risk
CVE-2026-12877
CVE-2026-12877
Summary
The WordPress Project Management Plugin is vulnerable to SQL injection attacks. This means attackers can potentially access or manipulate sensitive data in the plugin. Update the plugin to version 5.1.0 or later to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| unknown | project management, bug and issue tracking plugin | < 5.1.0 |
Original title
Software Issue Manager < 5.1.0 - Unauthenticated SQL Injection via Search Parameter
Original description
The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is exploitable in the Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0's standard front-end issue-tracker configuration.
Vulnerability type
CWE-287
Improper Authentication
Published: 24 Jul 2026 · Updated: 25 Jul 2026 · First seen: 24 Jul 2026