Extension WordPress

Vulnérabilités Zephyr Project Manager

Cette page rassemble les failles publiées pour Zephyr Project Manager, leurs plages de versions affectées et les correctifs signalés dans la base locale.

20Vulnérabilités
1Critiques
20Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Zephyr Project Manager

20 fiches

CVE-2025-12496 Moyenne · 4,9
Zephyr Project Manager

Zephyr Project Manager <= 3.3.203 – Authenticated (Custom+) Arbitrary File Read And Server-Side Request Forgery

The Zephyr Project Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.203 via the `file` parameter. This makes it possible for authenticated attackers, with Custom-level access and above, to read…

Versions affectées

*-3.3.203

Correctif

3.3.204

Publication

16/12/2025

CVE-2025-10490 Moyenne · 4,4
Zephyr Project Manager

Zephyr Project Manager <= 3.3.202 – Authenticated (Admin+) Stored Cross-Site Scripting

The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.3.202 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-3.3.202

Correctif

3.3.203

Publication

25/09/2025

CVE-2024-43916 Moyenne · 4,3
Zephyr Project Manager

Zephyr Project Manager <= 3.3.102 – Missing Authorization to Authenticated (Subscriber+) Status Updates

The Zephyr Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the via the 'create_status‘, ‘update_status‘, and ‘delete_status‘ functions in all versions up to, and including, 3.3.102. This…

Versions affectées

*-3.3.102

Correctif

3.3.103

Publication

20/08/2024

CVE-2024-7356 Moyenne · 6,4
Zephyr Project Manager

Zephyr Project Manager <= 3.3.100 – Authenticated (Subscriber+) Stored Cross-Site Scripting via filename Parameter

The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘filename’ parameter in all versions up to, and including, 3.3.100 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-3.3.100

Correctif

3.3.101

Publication

02/08/2024

CVE-2024-6536 Moyenne · 4,4
Zephyr Project Manager

Zephyr Project Manager <= 3.3.97 – Authenticated (Editor+) Stored Cross-Site Scripting

The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 3.3.97 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

Versions affectées

*-3.3.97

Correctif

3.3.99

Publication

09/07/2024

CVE-2024-37484 Élevée · 8,8
Zephyr Project Manager

Zephyr Project Manager <= 3.3.97 – Authenticated (Subscriber+) Privilege Escalation via User Meta Update

The Zephyr Project Manager plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.97. This is due to the plugin not properly verifying user meta updated through the update_user_meta function. This makes…

Versions affectées

*-3.3.97

Correctif

3.3.99

Publication

04/07/2024

Vulnérabilité Élevée · 7,2
Zephyr Project Manager

Zephyr Project Manager <= 3.2.42 – Missing Authorization to Cross-Site Scripting

The Zephyr Project Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and lack of authentication/authorization on its REST endpoints in versions up to, and including, 3.2.42. This makes it possible for…

Versions affectées

*-3.2.4, 3.2.41, 3.2.42

Correctif

3.2.5

Publication

29/08/2022

CVE-2022-1822 Moyenne · 6,1
Zephyr Project Manager

Zephyr Project Manager <= 3.2.40 – Reflected Cross-Site Scripting

The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘project’ parameter in versions up to, and including, 3.2.40 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

*-3.2.4, 3.2.40

Correctif

3.2.41, 3.2.5

Publication

23/05/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités