Projectopia
cpe:2.3:a:projectopia:projectopia:*:*:*:*:wordpress:*:*
- <= 5.1.19
A vulnerability exists in the Projectopia WordPress Project Management plugin, specifically in versions through 5.1.19. The issue arises from a missing capability check on the 'pto_delete_file' AJAX action, which enables unauthenticated attackers to delete arbitrary attachments. This unauthorized data modification could lead to the loss of important files or disrupt project management activities.
Exploitation of this vulnerability allows for the unauthorized deletion of attachments, which could result in the loss of important data or files associated with projects or tasks.
No known patch is available for this vulnerability. It is recommended to review the vulnerability details and consider uninstalling the affected plugin.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.