Input validation vulnerability in Zephyr Project Manager 3.3.100

The tool called Zephyr Project Manager, which is used with WordPress, has a security issue that allows hackers to inject harmful code into web pages. This can happen because the plugin does not properly clean up the input it receives or protect the output it displays. As a result, attackers who have at least Subscriber-level access can add their own code to pages and it will run whenever a user visits that page.

Detected in:

Zephyr Project Manager open vulnerable versions: >= * <= 3.3.100

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.