CVE-2025-32280
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2025-32280 is a Cross-Site Request Forgery (CSRF) vulnerability affecting weDevs WP Project Manager. This issue allows malicious actors to manipulate user sessions and execute unwanted actions on behalf of an affected user. The vulnerability exists in versions of WP Project Manager ranging from not available to 2.6.22, putting a significant number of users at risk. Successful exploitation can lead to unauthorized modifications, such as changing project information or adding new users, potentially compromising the affected WordPress installation. Users are advised to update to the latest version of WP Project Manager to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Wedevs Wp Project Manager
Affected Vendors
- weDevs