CVE-2026-74928 - WP Project Manager 2.1.0 - 4.0.6 - Unauthenticated Subscriber Account Creation via Trello Import Routes
CVE ID :CVE-2026-74928
Published : Aug. 26, 2026, 6 a.m. | 29 minutes ago
Description :The Project Manager WordPress plugin before 4.0.7 does not have any authorisation check on its import routes, allowing unauthenticated users to create WordPress accounts with a password the attacker already knows, bypassing the site's own registration setting.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 26, 2026, 6 a.m. | 29 minutes ago
Description :The Project Manager WordPress plugin before 4.0.7 does not have any authorisation check on its import routes, allowing unauthenticated users to create WordPress accounts with a password the attacker already knows, bypassing the site's own registration setting.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...