Extension WordPress
Vulnérabilités Zephyr Project Manager
Cette page rassemble les failles publiées pour Zephyr Project Manager, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Zephyr Project Manager
20 fiches
Zephyr Project Manager <= 3.3.203 – Authenticated (Custom+) Arbitrary File Read And Server-Side Request Forgery
The Zephyr Project Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.203 via the `file` parameter. This makes it possible for authenticated attackers, with Custom-level access and above, to read…
*-3.3.203
3.3.204
16/12/2025
Zephyr Project Manager <= 3.3.202 – Authenticated (Admin+) Stored Cross-Site Scripting
The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.3.202 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-3.3.202
3.3.203
25/09/2025
Zephyr Project Manager <= 3.3.201 – Missing Authorization
The Zephyr Project Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.3.201. This makes it possible for authenticated attackers, with Subscriber-level…
*-3.3.201
3.3.202
26/08/2025
Zephyr Project Manager <= 3.3.200 – Missing Authorization
The Zephyr Project Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.3.200. This makes it possible for authenticated attackers, with Subscriber-level…
*-3.3.200
3.3.201
16/04/2025
Zephyr Project Manager <= 3.3.101 – Reflected Cross-Site Scripting
The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.3.101 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
*-3.3.101
3.3.102
10/04/2025
Zephyr Project Manager <= 3.3.102 – Reflected Cross-Site Scripting
The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.3.102 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
*-3.3.102
3.3.103
20/08/2024
Zephyr Project Manager <= 3.3.102 – Missing Authorization to Authenticated (Subscriber+) Status Updates
The Zephyr Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the via the 'create_status‘, ‘update_status‘, and ‘delete_status‘ functions in all versions up to, and including, 3.3.102. This…
*-3.3.102
3.3.103
20/08/2024
Zephyr Project Manager <= 3.3.100 – Authenticated (Subscriber+) Insecure Direct Object Reference
The Zephyr Project Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.100 via the updateTaskStatus() due to missing validation on a user controlled key. This makes it possible…
*-3.3.100
3.3.101
16/08/2024
Zephyr Project Manager <= 3.3.101 – Authenticated (Subscriber+) Limited Privilege Escalation
The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is due to the plugin not properly checking a users capabilities before allowing them to enable…
*-3.3.101
3.3.102
14/08/2024
Zephyr Project Manager <= 3.3.100 – Authenticated (Subscriber+) Stored Cross-Site Scripting via filename Parameter
The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘filename’ parameter in all versions up to, and including, 3.3.100 due to insufficient input sanitization and output escaping. This makes it possible for…
*-3.3.100
3.3.101
02/08/2024
Zephyr Project Manager <= 3.3.99 – Unauthenticated Information Exposure
The Zephyr Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.99 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information…
*-3.3.99
3.3.100
12/07/2024
Zephyr Project Manager <= 3.3.97 – Authenticated (Editor+) Stored Cross-Site Scripting
The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 3.3.97 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-3.3.97
3.3.99
09/07/2024
Zephyr Project Manager <= 3.3.97 – Authenticated (Subscriber+) Privilege Escalation via User Meta Update
The Zephyr Project Manager plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.97. This is due to the plugin not properly verifying user meta updated through the update_user_meta function. This makes…
*-3.3.97
3.3.99
04/07/2024
Zephyr Project Manager <= 3.3.93 – Cross-Site Request Forgery
The Zephyr Project Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.93. This is due to missing or incorrect nonce validation in the ~/templates/settings.php file. This makes it possible for…
*-3.3.93
3.3.94
13/06/2023
Zephyr Project Manager <= 3.3.9 – Open Redirect
The Zephyr Project Manager plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 3.3.9. This is due to insufficient validation on the redirect url supplied via the 'redirect_to' parameter. This makes it possible…
*-3.3.9
3.3.10
27/04/2023
Zephyr Project Manager < 3.2.55 – Missing Authorization to Cross-Site Scripting
The Zephyr Project Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and lack of authentication/authorization on its AJAX endpoints in versions up to 3.2.55. This makes it possible for unauthenticated attackers…
[*, 3.2.55)
3.2.55
08/09/2022
Zephyr Project Manager <= 3.2.42 – Unauthenticated SQL Injection
The Zephyr Project Manager plugin for WordPress is vulnerable to SQL Injection via several parameters in versions up to, and including, 3.2.42 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
*-3.2.4, 3.2.41, 3.2.42
3.2.5
29/08/2022
Zephyr Project Manager <= 3.2.42 – Missing Authorization to Cross-Site Scripting
The Zephyr Project Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and lack of authentication/authorization on its REST endpoints in versions up to, and including, 3.2.42. This makes it possible for…
*-3.2.4, 3.2.41, 3.2.42
3.2.5
29/08/2022
Zephyr Project Manager <= 3.2.42 – Reflected Cross-Site Scripting
The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.2.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
[*, 3.2.5)
3.2.5
29/08/2022
Zephyr Project Manager <= 3.2.40 – Reflected Cross-Site Scripting
The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘project’ parameter in versions up to, and including, 3.2.40 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-3.2.4, 3.2.40
3.2.41, 3.2.5
23/05/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.