CVE-2025-32280

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Apr 4, 2025
Updated: Apr 9, 2025
CWE ID 352

Summary

CVE-2025-32280 is a Cross-Site Request Forgery (CSRF) vulnerability affecting weDevs WP Project Manager. This issue allows malicious actors to manipulate user sessions and execute unwanted actions on behalf of an affected user. The vulnerability exists in versions of WP Project Manager ranging from not available to 2.6.22, putting a significant number of users at risk. Successful exploitation can lead to unauthorized modifications, such as changing project information or adding new users, potentially compromising the affected WordPress installation. Users are advised to update to the latest version of WP Project Manager to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Wedevs Wp Project Manager

Affected Vendors

  • weDevs