CVE-2026-12877
A WordPress plugin that manages projects and issues is vulnerable to SQL injection because it fails to sanitize user input. Attackers can send crafted data to the plugin’s front‑end and run arbitrary SQL commands.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
The Project Management, Bug and Issue Tracking Plugin for WordPress, versions earlier than 5.1.0. Site owners running the plugin on any WordPress installation are at risk.
Real-world impact
An attacker could read, modify, or delete data in the WordPress database, potentially exposing sensitive information or disrupting site operations.
Why this severity
The CVSS score of 9.1 reflects that the flaw is exploitable over the network, requires no authentication, and can lead to complete compromise of the database, which is a high impact to confidentiality and integrity.
What to do about it
- 01Upgrade the Project Management, Bug and Issue Tracking Plugin to version 5.1.0 or later.
NVD-referenced vendor advisory
Timeline
- Jul 24, 2026 · 8d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 7d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.