plugin

Zephyr Project Manager Vulnerabilities

45 known security issues reported for the Zephyr Project Manager WordPress plugin. Most recent disclosed Dec 17, 2025.

1 critical 4 high 15 medium

Running Zephyr Project Manager on your site? Check whether your installed version is affected.

Scan your site free

Zephyr Project Manager [zephyr-project-manager] < 3.3.204

unknown

[en] The Zephyr Project Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.203 via the `file` parameter. This makes it possible for authenticated attackers, with Custom-level access and above, to read the contents of arbitrary files on the server, which can conta...

Affected:
up to 3.3.204
Fixed in:
3.3.204
Disclosed:
Dec 17, 2025

CVE-2025-12496 on NVD →

Zephyr Project Manager <= 3.3.203 - Authenticated (Custom+) Arbitrary File Read And Server-Side Request Forgery

medium

The Zephyr Project Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.203 via the `file` parameter. This makes it possible for authenticated attackers, with Custom-level access and above, to read the contents of arbitrary files on the server, which can contain se...

CVSS:
4.9
Affected:
up to 3.3.203
Fixed in:
3.3.204
Disclosed:
Dec 16, 2025

CVE-2025-12496 on NVD →

Zephyr Project Manager <= 3.3.202 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.3.202 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...

CVSS:
4.4
Affected:
up to 3.3.202
Fixed in:
3.3.203
Disclosed:
Sep 25, 2025

CVE-2025-10490 on NVD →

Zephyr Project Manager [zephyr-project-manager] < 3.3.202

unknown

[en] Missing Authorization vulnerability in Dylan James Zephyr Project Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Zephyr Project Manager: from n/a through 3.3.201.

Affected:
up to 3.3.202
Fixed in:
3.3.202
Disclosed:
Aug 28, 2025

CVE-2025-54714 on NVD →

Zephyr Project Manager <= 3.3.201 - Missing Authorization

medium

The Zephyr Project Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.3.201. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 3.3.201
Fixed in:
3.3.202
Disclosed:
Aug 26, 2025

CVE-2025-54714 on NVD →

Zephyr Project Manager [zephyr-project-manager] < 3.3.102

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager allows Reflected XSS. This issue affects Zephyr Project Manager: from n/a through 3.3.101.

Affected:
up to 3.3.102
Fixed in:
3.3.102
Disclosed:
Apr 17, 2025

CVE-2025-32526 on NVD →

Zephyr Project Manager <= 3.3.200 - Missing Authorization

medium

The Zephyr Project Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.3.200. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 3.3.200
Fixed in:
3.3.201
Disclosed:
Apr 16, 2025

CVE-2025-39552 on NVD →

Zephyr Project Manager [zephyr-project-manager] < 3.3.201

unknown

[en] Missing Authorization vulnerability in Dylan James Zephyr Project Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Zephyr Project Manager: from n/a through 3.3.200.

Affected:
up to 3.3.201
Fixed in:
3.3.201
Disclosed:
Apr 16, 2025

CVE-2025-39552 on NVD →

Zephyr Project Manager <= 3.3.101 - Reflected Cross-Site Scripting

medium

The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.3.101 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...

CVSS:
6.1
Affected:
up to 3.3.101
Fixed in:
3.3.102
Disclosed:
Apr 10, 2025

CVE-2025-32526 on NVD →

Zephyr Project Manager [zephyr-project-manager] < 3.3.103

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager allows Reflected XSS.This issue affects Zephyr Project Manager: from n/a through .3.102.

Affected:
up to 3.3.103
Fixed in:
3.3.103
Disclosed:
Aug 26, 2024

CVE-2024-43915 on NVD →

Zephyr Project Manager [zephyr-project-manager] < 3.3.103

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.102.

Affected:
up to 3.3.103
Fixed in:
3.3.103
Disclosed:
Aug 26, 2024

CVE-2024-43916 on NVD →

Zephyr Project Manager <= 3.3.102 - Reflected Cross-Site Scripting

medium

The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.3.102 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...

CVSS:
5.5
Affected:
up to 3.3.102
Fixed in:
3.3.103
Disclosed:
Aug 20, 2024

CVE-2024-43915 on NVD →

Zephyr Project Manager <= 3.3.102 - Missing Authorization to Authenticated (Subscriber+) Status Updates

medium

The Zephyr Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the via the 'create_status‘, ‘update_status‘, and ‘delete_status‘ functions in all versions up to, and including, 3.3.102. This makes it possible for authenticated attackers, with Subs...

CVSS:
4.3
Affected:
up to 3.3.102
Fixed in:
3.3.103
Disclosed:
Aug 20, 2024

CVE-2024-43916 on NVD →

Zephyr Project Manager [zephyr-project-manager] < 3.3.101

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.100.

Affected:
up to 3.3.101
Fixed in:
3.3.101
Disclosed:
Aug 18, 2024

CVE-2024-43322 on NVD →

Zephyr Project Manager <= 3.3.100 - Authenticated (Subscriber+) Insecure Direct Object Reference

medium

The Zephyr Project Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.100 via the updateTaskStatus() due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to edit task statuses that do not belong to...

CVSS:
4.3
Affected:
up to 3.3.100
Fixed in:
3.3.101
Disclosed:
Aug 16, 2024

CVE-2024-43322 on NVD →

Zephyr Project Manager [zephyr-project-manager] < 3.3.102

unknown

[en] The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is due to the plugin not properly checking a users capabilities before allowing them to enable access to the plugin's settings through the update_user_access() function....

Affected:
up to 3.3.102
Fixed in:
3.3.102
Disclosed:
Aug 15, 2024

CVE-2024-7624 on NVD →

Zephyr Project Manager <= 3.3.101 - Authenticated (Subscriber+) Limited Privilege Escalation

high

The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is due to the plugin not properly checking a users capabilities before allowing them to enable access to the plugin's settings through the update_user_access() function. This...

CVSS:
8.1
Affected:
up to 3.3.101
Fixed in:
3.3.102
Disclosed:
Aug 14, 2024

CVE-2024-7624 on NVD →

Zephyr Project Manager [zephyr-project-manager] < 3.3.101

unknown

[en] The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘filename’ parameter in all versions up to, and including, 3.3.100 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and ab...

Affected:
up to 3.3.101
Fixed in:
3.3.101
Disclosed:
Aug 3, 2024

CVE-2024-7356 on NVD →

Zephyr Project Manager <= 3.3.100 - Authenticated (Subscriber+) Stored Cross-Site Scripting via filename Parameter

medium

The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘filename’ parameter in all versions up to, and including, 3.3.100 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above,...

CVSS:
6.4
Affected:
up to 3.3.100
Fixed in:
3.3.101
Disclosed:
Aug 2, 2024

CVE-2024-7356 on NVD →

Zephyr Project Manager [zephyr-project-manager] < 3.3.100

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.99.

Affected:
up to 3.3.100
Fixed in:
3.3.100
Disclosed:
Aug 1, 2024

CVE-2024-38761 on NVD →

Zephyr Project Manager [zephyr-project-manager] < 3.3.99

unknown

[en] The Zephyr Project Manager WordPress plugin before 3.3.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors and admins to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 3.3.99
Fixed in:
3.3.99
Disclosed:
Jul 30, 2024

CVE-2024-6536 on NVD →

Zephyr Project Manager <= 3.3.99 - Unauthenticated Information Exposure

medium

The Zephyr Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.99 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.

CVSS:
5.3
Affected:
up to 3.3.99
Fixed in:
3.3.100
Disclosed:
Jul 12, 2024

CVE-2024-38761 on NVD →

Zephyr Project Manager <= 3.3.97 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 3.3.97 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitr...

CVSS:
4.4
Affected:
up to 3.3.97
Fixed in:
3.3.99
Disclosed:
Jul 9, 2024

CVE-2024-6536 on NVD →

Zephyr Project Manager [zephyr-project-manager] < 3.3.99

unknown

[en] Improper Privilege Management vulnerability in Dylan James Zephyr Project Manager allows Privilege Escalation.This issue affects Zephyr Project Manager: from n/a through 3.3.97.

Affected:
up to 3.3.99
Fixed in:
3.3.99
Disclosed:
Jul 9, 2024

CVE-2024-37484 on NVD →

Zephyr Project Manager <= 3.3.97 - Authenticated (Subscriber+) Privilege Escalation via User Meta Update

high

The Zephyr Project Manager plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.97. This is due to the plugin not properly verifying user meta updated through the update_user_meta function. This makes it possible for authenticated attackers, with subscriber-level access a...

CVSS:
8.8
Affected:
up to 3.3.97
Fixed in:
3.3.99
Disclosed:
Jul 4, 2024

CVE-2024-37484 on NVD →

Zephyr Project Manager [zephyr-project-manager] < 3.3.10

unknown

[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.9.

Affected:
up to 3.3.10
Fixed in:
3.3.10
Disclosed:
Dec 29, 2023

CVE-2023-31237 on NVD →

Zephyr Project Manager [zephyr-project-manager] < 3.3.94

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Dylan James Zephyr Project Manager plugin <= 3.3.93 versions.

Affected:
up to 3.3.94
Fixed in:
3.3.94
Disclosed:
Jun 19, 2023

CVE-2023-34373 on NVD →

Zephyr Project Manager <= 3.3.93 - Cross-Site Request Forgery

medium

The Zephyr Project Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.93. This is due to missing or incorrect nonce validation in the ~/templates/settings.php file. This makes it possible for unauthenticated attackers to delete all plugin data via a forged req...

CVSS:
4.3
Affected:
up to 3.3.93
Fixed in:
3.3.94
Disclosed:
Jun 13, 2023

CVE-2023-34373 on NVD →

Zephyr Project Manager <= 3.3.9 - Open Redirect

medium

The Zephyr Project Manager plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 3.3.9. This is due to insufficient validation on the redirect url supplied via the 'redirect_to' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sit...

CVSS:
5.4
Affected:
up to 3.3.9
Fixed in:
3.3.10
Disclosed:
Apr 27, 2023

CVE-2023-31237 on NVD →

Zephyr Project Manager [zephyr-project-manager] < 3.2.55

unknown

[en] The Zephyr Project Manager WordPress plugin before 3.2.55 does not have any authorisation as well as CSRF in all its AJAX actions, allowing unauthenticated users to call them either directly or via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also allow them to perform Stored C...

Affected:
up to 3.2.55
Fixed in:
3.2.55
Disclosed:
Oct 3, 2022

CVE-2022-2839 on NVD →

Zephyr Project Manager [zephyr-project-manager] < 3.2.5

unknown

[en] A vulnerability, which was classified as problematic, was found in Zephyr Project Manager up to 3.2.4. Affected is an unknown function of the file /v1/tasks/create/ of the component REST Call Handler. The manipulation of the argument onanimationstart leads to cross site scripting. It is possible to launch the atta...

Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
Sep 28, 2022

CVE-2022-3333 on NVD →

Zephyr Project Manager [zephyr-project-manager] < 3.2.5

unknown

[en] The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections

Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
Sep 19, 2022

CVE-2022-2840 on NVD →

Zephyr Project Manager < 3.2.55 - Missing Authorization to Cross-Site Scripting

high

The Zephyr Project Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and lack of authentication/authorization on its AJAX endpoints in versions up to 3.2.55. This makes it possible for unauthenticated attackers to utilize them. Additionally, user input is not properly...

CVSS:
7.2
Affected:
up to 3.2.55
Fixed in:
3.2.55
Disclosed:
Sep 8, 2022

CVE-2022-2839 on NVD →

Zephyr Project Manager <= 3.2.42 - Unauthenticated SQL Injection

critical

The Zephyr Project Manager plugin for WordPress is vulnerable to SQL Injection via several parameters in versions up to, and including, 3.2.42 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to...

CVSS:
9.8
Affected:
up to 3.2.4, 3.2.41 – 3.2.41, 3.2.42 – 3.2.42
Fixed in:
3.2.5
Disclosed:
Aug 29, 2022

CVE-2022-2840 on NVD →

Zephyr Project Manager <= 3.2.42 - Missing Authorization to Cross-Site Scripting

high

The Zephyr Project Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and lack of authentication/authorization on its REST endpoints in versions up to, and including, 3.2.42. This makes it possible for unauthenticated attackers to utilize them. Additionally, user input...

CVSS:
7.2
Affected:
up to 3.2.4, 3.2.41 – 3.2.41, 3.2.42 – 3.2.42
Fixed in:
3.2.5
Disclosed:
Aug 29, 2022

Zephyr Project Manager <= 3.2.42 - Reflected Cross-Site Scripting

medium

The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.2.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succ...

CVSS:
6.1
Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
Aug 29, 2022

Zephyr Project Manager [zephyr-project-manager] < 3.2.5

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScan in WordPress Zephyr Project Manager plugin (versions <= 3.2.42). Update the WordPress Zephyr Project Manager plugin to the latest available version (at least 3.2.5).

Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
Aug 29, 2022

Zephyr Project Manager [zephyr-project-manager] < 3.2.5

unknown

The Zephyr Project Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and lack of authentication/authorization on its REST endpoints in versions up to, and including, 3.2.42. This makes it possible for unauthenticated attackers to utilize them. Additionally, user input...

Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
Aug 29, 2022

Zephyr Project Manager [zephyr-project-manager] < 3.2.5

unknown

The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.2.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succ...

Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
Aug 29, 2022

Zephyr Project Manager [zephyr-project-manager] < 3.2.5

unknown

Unauthorized REST Calls to Stored Cross-Site Scripting (XSS) vulnerability discovered by WPScan in WordPress Zephyr Project Manager plugin (versions <= 3.2.42). Update the WordPress Zephyr Project Manager plugin to the latest available version (at least 3.2.5).

Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
Aug 29, 2022

Zephyr Project Manager [zephyr-project-manager] < 3.2.41

unknown

[en] The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘project’ parameter in versions up to, and including, 3.2.40 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...

Affected:
up to 3.2.41
Fixed in:
3.2.41
Disclosed:
Jun 13, 2022

CVE-2022-1822 on NVD →

Zephyr Project Manager <= 3.2.40 - Reflected Cross-Site Scripting

medium

The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘project’ parameter in versions up to, and including, 3.2.40 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t...

CVSS:
6.1
Affected:
up to 3.2.4, 3.2.40 – 3.2.40
Fixed in:
3.2.41
Disclosed:
May 23, 2022

CVE-2022-1822 on NVD →

Zephyr Project Manager [zephyr-project-manager] < 3.2.5

unknown

The plugin does not have proper authorisation (even when the Require Authorisation for REST API Requests is enabled) in all its REST endpoints, allowing unauthenticated users to call them either directly. Furthermore, due to the lack of sanitisation and escaping, it could also allow them to perform Stored Cross-Site Sc...

Affected:
up to 3.2.5
Fixed in:
3.2.5

Zephyr Project Manager [zephyr-project-manager] < 3.2.5

unknown

The plugin does not sanitise and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

Affected:
up to 3.2.5
Fixed in:
3.2.5

Zephyr Project Manager [zephyr-project-manager] < 3.3.203

unknown
Affected:
up to 3.3.203
Fixed in:
3.3.203

CVE-2025-10490 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database