The Zephyr Project Manager WordPress plugin before 3.3.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors and admins to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Metrics
Affected Vendors & Products
References
History
Tue, 10 Jun 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dylanjkotze
Dylanjkotze zephyr Project Manager |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:dylanjkotze:zephyr_project_manager:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Dylanjkotze
Dylanjkotze zephyr Project Manager |
Mon, 04 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dylanjames
Dylanjames zephyr Project Manager |
|
CPEs | cpe:2.3:a:dylanjames:zephyr_project_manager:*:*:*:*:*:*:*:* | |
Vendors & Products |
Dylanjames
Dylanjames zephyr Project Manager |
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: WPScan
Published: 2024-07-30T06:00:10.760Z
Updated: 2024-11-04T16:38:26.463Z
Reserved: 2024-07-05T20:00:20.656Z
Link: CVE-2024-6536

Updated: 2024-08-01T21:41:03.512Z

Status : Analyzed
Published: 2024-07-30T06:15:04.013
Modified: 2025-06-10T16:01:07.250
Link: CVE-2024-6536

No data.