Progress Planner Vulnerabilities and Affected Products
Vulnerabilities associated with Progress Planner.
Products
Clear product- Progress Planner3 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-48082HIGH | WordPress Progress Planner plugin <= 1.8.0 - Privilege Escalation vulnerabilityIncorrect Privilege Assignment vulnerability in Progress Planner Progress Planner progress-planner allows Privilege Escalation.This issue affects Progress Planner: from n/a through <= 1.8.0. CWE-266Oct 22, 2025 | CVSS8.8v3.1 | EPSS0.449% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-37411MEDIUM | WordPress Progress Planner plugin <= 0.9.1 - Broken Access Control vulnerabilityMissing Authorization vulnerability in Progress Planner Progress Planner progress-planner.This issue affects Progress Planner: from n/a through <= 0.9.1. CWE-862Nov 1, 2024 | CVSS5.3v3.1 | EPSS0.396% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-37422MEDIUM | WordPress Progress Planner plugin <= 0.9.2 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Progress Planner Progress Planner progress-planner.This issue affects Progress Planner: from n/a through <= 0.9.2. CWE-79Jul 22, 2024 | CVSS6.5v3.1 | EPSS0.261% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |