Zephyr Project Manager [zephyr-project-manager] < 3.3.204
unknown
[en] The Zephyr Project Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.203 via the `file` parameter. This makes it possible for authenticated attackers, with Custom-level access and above, to read the contents of arbitrary files on the server, which can conta...
- Affected:
- up to 3.3.204
- Fixed in:
- 3.3.204
- Disclosed:
- Dec 17, 2025
CVE-2025-12496 on NVD →
Zephyr Project Manager <= 3.3.203 - Authenticated (Custom+) Arbitrary File Read And Server-Side Request Forgery
medium
The Zephyr Project Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.203 via the `file` parameter. This makes it possible for authenticated attackers, with Custom-level access and above, to read the contents of arbitrary files on the server, which can contain se...
- CVSS:
- 4.9
- Affected:
- up to 3.3.203
- Fixed in:
- 3.3.204
- Disclosed:
- Dec 16, 2025
CVE-2025-12496 on NVD →
Zephyr Project Manager <= 3.3.202 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.3.202 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...
- CVSS:
- 4.4
- Affected:
- up to 3.3.202
- Fixed in:
- 3.3.203
- Disclosed:
- Sep 25, 2025
CVE-2025-10490 on NVD →
Zephyr Project Manager [zephyr-project-manager] < 3.3.202
unknown
[en] Missing Authorization vulnerability in Dylan James Zephyr Project Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Zephyr Project Manager: from n/a through 3.3.201.
- Affected:
- up to 3.3.202
- Fixed in:
- 3.3.202
- Disclosed:
- Aug 28, 2025
CVE-2025-54714 on NVD →
Zephyr Project Manager <= 3.3.201 - Missing Authorization
medium
The Zephyr Project Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.3.201. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 3.3.201
- Fixed in:
- 3.3.202
- Disclosed:
- Aug 26, 2025
CVE-2025-54714 on NVD →
Zephyr Project Manager [zephyr-project-manager] < 3.3.102
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager allows Reflected XSS. This issue affects Zephyr Project Manager: from n/a through 3.3.101.
- Affected:
- up to 3.3.102
- Fixed in:
- 3.3.102
- Disclosed:
- Apr 17, 2025
CVE-2025-32526 on NVD →
Zephyr Project Manager <= 3.3.200 - Missing Authorization
medium
The Zephyr Project Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.3.200. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 3.3.200
- Fixed in:
- 3.3.201
- Disclosed:
- Apr 16, 2025
CVE-2025-39552 on NVD →
Zephyr Project Manager [zephyr-project-manager] < 3.3.201
unknown
[en] Missing Authorization vulnerability in Dylan James Zephyr Project Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Zephyr Project Manager: from n/a through 3.3.200.
- Affected:
- up to 3.3.201
- Fixed in:
- 3.3.201
- Disclosed:
- Apr 16, 2025
CVE-2025-39552 on NVD →
Zephyr Project Manager <= 3.3.101 - Reflected Cross-Site Scripting
medium
The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.3.101 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...
- CVSS:
- 6.1
- Affected:
- up to 3.3.101
- Fixed in:
- 3.3.102
- Disclosed:
- Apr 10, 2025
CVE-2025-32526 on NVD →
Zephyr Project Manager [zephyr-project-manager] < 3.3.103
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager allows Reflected XSS.This issue affects Zephyr Project Manager: from n/a through .3.102.
- Affected:
- up to 3.3.103
- Fixed in:
- 3.3.103
- Disclosed:
- Aug 26, 2024
CVE-2024-43915 on NVD →
Zephyr Project Manager [zephyr-project-manager] < 3.3.103
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.102.
- Affected:
- up to 3.3.103
- Fixed in:
- 3.3.103
- Disclosed:
- Aug 26, 2024
CVE-2024-43916 on NVD →
Zephyr Project Manager <= 3.3.102 - Reflected Cross-Site Scripting
medium
The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.3.102 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...
- CVSS:
- 5.5
- Affected:
- up to 3.3.102
- Fixed in:
- 3.3.103
- Disclosed:
- Aug 20, 2024
CVE-2024-43915 on NVD →
Zephyr Project Manager <= 3.3.102 - Missing Authorization to Authenticated (Subscriber+) Status Updates
medium
The Zephyr Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the via the 'create_status‘, ‘update_status‘, and ‘delete_status‘ functions in all versions up to, and including, 3.3.102. This makes it possible for authenticated attackers, with Subs...
- CVSS:
- 4.3
- Affected:
- up to 3.3.102
- Fixed in:
- 3.3.103
- Disclosed:
- Aug 20, 2024
CVE-2024-43916 on NVD →
Zephyr Project Manager [zephyr-project-manager] < 3.3.101
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.100.
- Affected:
- up to 3.3.101
- Fixed in:
- 3.3.101
- Disclosed:
- Aug 18, 2024
CVE-2024-43322 on NVD →
Zephyr Project Manager <= 3.3.100 - Authenticated (Subscriber+) Insecure Direct Object Reference
medium
The Zephyr Project Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.100 via the updateTaskStatus() due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to edit task statuses that do not belong to...
- CVSS:
- 4.3
- Affected:
- up to 3.3.100
- Fixed in:
- 3.3.101
- Disclosed:
- Aug 16, 2024
CVE-2024-43322 on NVD →
Zephyr Project Manager [zephyr-project-manager] < 3.3.102
unknown
[en] The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is due to the plugin not properly checking a users capabilities before allowing them to enable access to the plugin's settings through the update_user_access() function....
- Affected:
- up to 3.3.102
- Fixed in:
- 3.3.102
- Disclosed:
- Aug 15, 2024
CVE-2024-7624 on NVD →
Zephyr Project Manager <= 3.3.101 - Authenticated (Subscriber+) Limited Privilege Escalation
high
The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is due to the plugin not properly checking a users capabilities before allowing them to enable access to the plugin's settings through the update_user_access() function. This...
- CVSS:
- 8.1
- Affected:
- up to 3.3.101
- Fixed in:
- 3.3.102
- Disclosed:
- Aug 14, 2024
CVE-2024-7624 on NVD →
Zephyr Project Manager [zephyr-project-manager] < 3.3.101
unknown
[en] The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘filename’ parameter in all versions up to, and including, 3.3.100 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and ab...
- Affected:
- up to 3.3.101
- Fixed in:
- 3.3.101
- Disclosed:
- Aug 3, 2024
CVE-2024-7356 on NVD →
Zephyr Project Manager <= 3.3.100 - Authenticated (Subscriber+) Stored Cross-Site Scripting via filename Parameter
medium
The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘filename’ parameter in all versions up to, and including, 3.3.100 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above,...
- CVSS:
- 6.4
- Affected:
- up to 3.3.100
- Fixed in:
- 3.3.101
- Disclosed:
- Aug 2, 2024
CVE-2024-7356 on NVD →
Zephyr Project Manager [zephyr-project-manager] < 3.3.100
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.99.
- Affected:
- up to 3.3.100
- Fixed in:
- 3.3.100
- Disclosed:
- Aug 1, 2024
CVE-2024-38761 on NVD →
Zephyr Project Manager [zephyr-project-manager] < 3.3.99
unknown
[en] The Zephyr Project Manager WordPress plugin before 3.3.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors and admins to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 3.3.99
- Fixed in:
- 3.3.99
- Disclosed:
- Jul 30, 2024
CVE-2024-6536 on NVD →
Zephyr Project Manager <= 3.3.99 - Unauthenticated Information Exposure
medium
The Zephyr Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.99 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.
- CVSS:
- 5.3
- Affected:
- up to 3.3.99
- Fixed in:
- 3.3.100
- Disclosed:
- Jul 12, 2024
CVE-2024-38761 on NVD →
Zephyr Project Manager <= 3.3.97 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 3.3.97 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitr...
- CVSS:
- 4.4
- Affected:
- up to 3.3.97
- Fixed in:
- 3.3.99
- Disclosed:
- Jul 9, 2024
CVE-2024-6536 on NVD →
Zephyr Project Manager [zephyr-project-manager] < 3.3.99
unknown
[en] Improper Privilege Management vulnerability in Dylan James Zephyr Project Manager allows Privilege Escalation.This issue affects Zephyr Project Manager: from n/a through 3.3.97.
- Affected:
- up to 3.3.99
- Fixed in:
- 3.3.99
- Disclosed:
- Jul 9, 2024
CVE-2024-37484 on NVD →
Zephyr Project Manager <= 3.3.97 - Authenticated (Subscriber+) Privilege Escalation via User Meta Update
high
The Zephyr Project Manager plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.97. This is due to the plugin not properly verifying user meta updated through the update_user_meta function. This makes it possible for authenticated attackers, with subscriber-level access a...
- CVSS:
- 8.8
- Affected:
- up to 3.3.97
- Fixed in:
- 3.3.99
- Disclosed:
- Jul 4, 2024
CVE-2024-37484 on NVD →
Zephyr Project Manager [zephyr-project-manager] < 3.3.10
unknown
[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.9.
- Affected:
- up to 3.3.10
- Fixed in:
- 3.3.10
- Disclosed:
- Dec 29, 2023
CVE-2023-31237 on NVD →
Zephyr Project Manager [zephyr-project-manager] < 3.3.94
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Dylan James Zephyr Project Manager plugin <= 3.3.93 versions.
- Affected:
- up to 3.3.94
- Fixed in:
- 3.3.94
- Disclosed:
- Jun 19, 2023
CVE-2023-34373 on NVD →
Zephyr Project Manager <= 3.3.93 - Cross-Site Request Forgery
medium
The Zephyr Project Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.93. This is due to missing or incorrect nonce validation in the ~/templates/settings.php file. This makes it possible for unauthenticated attackers to delete all plugin data via a forged req...
- CVSS:
- 4.3
- Affected:
- up to 3.3.93
- Fixed in:
- 3.3.94
- Disclosed:
- Jun 13, 2023
CVE-2023-34373 on NVD →
Zephyr Project Manager <= 3.3.9 - Open Redirect
medium
The Zephyr Project Manager plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 3.3.9. This is due to insufficient validation on the redirect url supplied via the 'redirect_to' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sit...
- CVSS:
- 5.4
- Affected:
- up to 3.3.9
- Fixed in:
- 3.3.10
- Disclosed:
- Apr 27, 2023
CVE-2023-31237 on NVD →
Zephyr Project Manager [zephyr-project-manager] < 3.2.55
unknown
[en] The Zephyr Project Manager WordPress plugin before 3.2.55 does not have any authorisation as well as CSRF in all its AJAX actions, allowing unauthenticated users to call them either directly or via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also allow them to perform Stored C...
- Affected:
- up to 3.2.55
- Fixed in:
- 3.2.55
- Disclosed:
- Oct 3, 2022
CVE-2022-2839 on NVD →
Zephyr Project Manager [zephyr-project-manager] < 3.2.5
unknown
[en] A vulnerability, which was classified as problematic, was found in Zephyr Project Manager up to 3.2.4. Affected is an unknown function of the file /v1/tasks/create/ of the component REST Call Handler. The manipulation of the argument onanimationstart leads to cross site scripting. It is possible to launch the atta...
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.5
- Disclosed:
- Sep 28, 2022
CVE-2022-3333 on NVD →
Zephyr Project Manager [zephyr-project-manager] < 3.2.5
unknown
[en] The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.5
- Disclosed:
- Sep 19, 2022
CVE-2022-2840 on NVD →
Zephyr Project Manager < 3.2.55 - Missing Authorization to Cross-Site Scripting
high
The Zephyr Project Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and lack of authentication/authorization on its AJAX endpoints in versions up to 3.2.55. This makes it possible for unauthenticated attackers to utilize them. Additionally, user input is not properly...
- CVSS:
- 7.2
- Affected:
- up to 3.2.55
- Fixed in:
- 3.2.55
- Disclosed:
- Sep 8, 2022
CVE-2022-2839 on NVD →
Zephyr Project Manager <= 3.2.42 - Unauthenticated SQL Injection
critical
The Zephyr Project Manager plugin for WordPress is vulnerable to SQL Injection via several parameters in versions up to, and including, 3.2.42 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to...
- CVSS:
- 9.8
- Affected:
- up to 3.2.4, 3.2.41 – 3.2.41, 3.2.42 – 3.2.42
- Fixed in:
- 3.2.5
- Disclosed:
- Aug 29, 2022
CVE-2022-2840 on NVD →
Zephyr Project Manager <= 3.2.42 - Missing Authorization to Cross-Site Scripting
high
The Zephyr Project Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and lack of authentication/authorization on its REST endpoints in versions up to, and including, 3.2.42. This makes it possible for unauthenticated attackers to utilize them. Additionally, user input...
- CVSS:
- 7.2
- Affected:
- up to 3.2.4, 3.2.41 – 3.2.41, 3.2.42 – 3.2.42
- Fixed in:
- 3.2.5
- Disclosed:
- Aug 29, 2022
Zephyr Project Manager <= 3.2.42 - Reflected Cross-Site Scripting
medium
The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.2.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succ...
- CVSS:
- 6.1
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.5
- Disclosed:
- Aug 29, 2022
Zephyr Project Manager [zephyr-project-manager] < 3.2.5
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScan in WordPress Zephyr Project Manager plugin (versions <= 3.2.42).
Update the WordPress Zephyr Project Manager plugin to the latest available version (at least 3.2.5).
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.5
- Disclosed:
- Aug 29, 2022
Zephyr Project Manager [zephyr-project-manager] < 3.2.5
unknown
The Zephyr Project Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and lack of authentication/authorization on its REST endpoints in versions up to, and including, 3.2.42. This makes it possible for unauthenticated attackers to utilize them. Additionally, user input...
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.5
- Disclosed:
- Aug 29, 2022
Zephyr Project Manager [zephyr-project-manager] < 3.2.5
unknown
The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.2.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succ...
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.5
- Disclosed:
- Aug 29, 2022
Zephyr Project Manager [zephyr-project-manager] < 3.2.5
unknown
Unauthorized REST Calls to Stored Cross-Site Scripting (XSS) vulnerability discovered by WPScan in WordPress Zephyr Project Manager plugin (versions <= 3.2.42).
Update the WordPress Zephyr Project Manager plugin to the latest available version (at least 3.2.5).
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.5
- Disclosed:
- Aug 29, 2022
Zephyr Project Manager [zephyr-project-manager] < 3.2.41
unknown
[en] The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘project’ parameter in versions up to, and including, 3.2.40 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...
- Affected:
- up to 3.2.41
- Fixed in:
- 3.2.41
- Disclosed:
- Jun 13, 2022
CVE-2022-1822 on NVD →
Zephyr Project Manager <= 3.2.40 - Reflected Cross-Site Scripting
medium
The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘project’ parameter in versions up to, and including, 3.2.40 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t...
- CVSS:
- 6.1
- Affected:
- up to 3.2.4, 3.2.40 – 3.2.40
- Fixed in:
- 3.2.41
- Disclosed:
- May 23, 2022
CVE-2022-1822 on NVD →
Zephyr Project Manager [zephyr-project-manager] < 3.2.5
unknown
The plugin does not have proper authorisation (even when the Require Authorisation for REST API Requests is enabled) in all its REST endpoints, allowing unauthenticated users to call them either directly. Furthermore, due to the lack of sanitisation and escaping, it could also allow them to perform Stored Cross-Site Sc...
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.5
Zephyr Project Manager [zephyr-project-manager] < 3.2.5
unknown
The plugin does not sanitise and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.5
Zephyr Project Manager [zephyr-project-manager] < 3.3.203
unknown
- Affected:
- up to 3.3.203
- Fixed in:
- 3.3.203
CVE-2025-10490 on NVD →