Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown

CVE-2024-43916

Disclosure Date: August 26, 2024 (last updated September 13, 2024)
Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.102.
Attacker Value
Unknown

CVE-2024-43915

Disclosure Date: August 26, 2024 (last updated August 29, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager allows Reflected XSS.This issue affects Zephyr Project Manager: from n/a through .3.102.
Attacker Value
Unknown

CVE-2024-43322

Disclosure Date: August 18, 2024 (last updated February 12, 2025)
Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.100.
Attacker Value
Unknown

CVE-2024-7624

Disclosure Date: August 15, 2024 (last updated February 12, 2025)
The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is due to the plugin not properly checking a users capabilities before allowing them to enable access to the plugin's settings through the update_user_access() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to grant themselves full access to the plugin's settings.
0
Attacker Value
Unknown

CVE-2024-7356

Disclosure Date: August 03, 2024 (last updated February 12, 2025)
The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘filename’ parameter in all versions up to, and including, 3.3.100 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-38761

Disclosure Date: August 01, 2024 (last updated February 12, 2025)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.99.
Attacker Value
Unknown

CVE-2024-6536

Disclosure Date: July 30, 2024 (last updated July 30, 2024)
The Zephyr Project Manager WordPress plugin before 3.3.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors and admins to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown

CVE-2024-37484

Disclosure Date: July 09, 2024 (last updated February 11, 2025)
Improper Privilege Management vulnerability in Dylan James Zephyr Project Manager allows Privilege Escalation.This issue affects Zephyr Project Manager: from n/a through 3.3.97.
Attacker Value
Unknown

CVE-2023-31237

Disclosure Date: December 29, 2023 (last updated January 06, 2024)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.9.
Attacker Value
Unknown

CVE-2023-34373

Disclosure Date: June 19, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Dylan James Zephyr Project Manager plugin <= 3.3.93 versions.