Input validation vulnerability in Zephyr Project Manager 3.2.4

The Zephyr Project Manager plugin for WordPress is vulnerable to a type of attack called Reflected Cross-Site Scripting. This type of attack can occur in versions up to and including 3.2.42 because of missing sanitization and output escaping. This means that unauthenticated attackers can inject malicious web scripts into pages that can be executed if a user is tricked into clicking on a link.

Detected in:

Zephyr Project Manager open vulnerable versions: >= * < 3.2.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.