← WordPress Vulnerabilities
WordPress security by component

Zephyr Project Manager

Zephyr Project Manager is a WordPress component with 18 published CVE records in this archive. The latest tracked vulnerability was published Dec 17, 2025; the highest CVE/CNA score is 9.8.

Plugin slug: zephyr-project-manager

CVE-2025-12496: Zephyr Project Manager: Filesystem traversal

Zephyr Project Manager is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.

PublishedDec 17, 2025
Safe version guidanceSee mitigation notes
Safe version
Dec 17, 2025 CVE-2025-12496
Zephyr Project Manager: Filesystem traversal
Zephyr Project Manager is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE4.9
NVDPending
Sep 26, 2025 CVE-2025-10490
Zephyr Project Manager: Cross-site scripting
Zephyr Project Manager is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVDPending
Aug 28, 2025 CVE-2025-54714
Zephyr Project Manager: A security weakness
Zephyr Project Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.1
NVDPending
Apr 17, 2025 CVE-2025-32526
Zephyr Project Manager: Cross-site scripting
Zephyr Project Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Apr 16, 2025 CVE-2025-39552
Zephyr Project Manager: A security weakness
Zephyr Project Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Aug 26, 2024 CVE-2024-43916
Zephyr Project Manager: A security weakness
Zephyr Project Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD7.1
Aug 26, 2024 CVE-2024-43915
Zephyr Project Manager: Cross-site scripting
Zephyr Project Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.5
NVD5.4
Aug 18, 2024 CVE-2024-43322
Zephyr Project Manager: A security weakness
Zephyr Project Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD9.8
Aug 15, 2024 CVE-2024-7624
Zephyr Project Manager: Privilege escalation or authentication bypass
Zephyr Project Manager is affected by privilege escalation or authentication bypass. Exploitation requires at least subscriber-level access. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.1
NVDPending
Aug 03, 2024 CVE-2024-7356
Zephyr Project Manager: Cross-site scripting
Zephyr Project Manager is affected by cross-site scripting. Exploitation requires at least subscriber-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Aug 01, 2024 CVE-2024-38761
Zephyr Project Manager: A security weakness
Zephyr Project Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Jul 30, 2024 CVE-2024-6536
Zephyr Project Manager: Cross-site scripting
Zephyr Project Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Jul 09, 2024 CVE-2024-37484
Zephyr Project Manager: Privilege escalation or authentication bypass
Zephyr Project Manager is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVD8.8
Dec 29, 2023 CVE-2023-31237
Zephyr Project Manager: An open redirect
Zephyr Project Manager is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
See mitigation notes
CVE4.7
NVD6.1
Jun 19, 2023 CVE-2023-34373
Zephyr Project Manager: Cross-site request forgery
Zephyr Project Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
Oct 03, 2022 CVE-2022-2839
Zephyr Project Manager: Cross-site scripting
Zephyr Project Manager is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Sep 19, 2022 CVE-2022-2840
Zephyr Project Manager: SQL injection
Zephyr Project Manager is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Jun 13, 2022 CVE-2022-1822
Zephyr Project Manager: Cross-site scripting
Zephyr Project Manager is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1