A vulnerability classified as critical has been found in wedevs WP Project Manager Plugin up to 2.6.17 on WordPress. This affects an unknown part. The manipulation of the argument orderby leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-13500. It is possible to initiate the attack remotely. There is no exploit available.