Vulnary
← back to the feed
Critical· 9.1official fix available

CVE-2026-12877

A WordPress plugin that manages projects and issues is vulnerable to SQL injection because it fails to sanitize user input. Attackers can send crafted data to the plugin’s front‑end and run arbitrary SQL commands.

publishedJul 24, 2026
last modifiedJul 24, 2026
sourcesNVD
severity · cvss
9.1
critical · how bad it is
exploitation · epss
<1%
15th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 23, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

The Project Management, Bug and Issue Tracking Plugin for WordPress, versions earlier than 5.1.0. Site owners running the plugin on any WordPress installation are at risk.

02

Real-world impact

An attacker could read, modify, or delete data in the WordPress database, potentially exposing sensitive information or disrupting site operations.

03

Why this severity

The CVSS score of 9.1 reflects that the flaw is exploitable over the network, requires no authentication, and can lead to complete compromise of the database, which is a high impact to confidentiality and integrity.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade the Project Management, Bug and Issue Tracking Plugin to version 5.1.0 or later.

NVD-referenced vendor advisory

05

Timeline

  1. Jul 24, 2026 · 8d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 24, 2026 · 7d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactNone
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →