Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-78262: WP Project Manager plugin can be taken over remotely
CVE-2026-78262 · published 10 days ago
Summary
Versions of the WP Project Manager plugin up to 4.0.6 let anyone on the internet send specially crafted data that can make the website run their own code. This could let attackers steal data, change site content, or use the server for other attacks. Update the plugin to the latest version or replace it with a safer alternative as soon as possible.
Original advisory text
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published24 Aug 2026
Updated2 Sep 2026
First seen24 Aug 2026
Sources
CVE-2026-78262 · NVD
Monitor software like this
Free during beta