Access violation vulnerability in Zephyr Project Manager 3.3.100

The Zephyr Project Manager plugin for WordPress has a security issue in all versions up to 3.3.100. This is because the updateTaskStatus() function does not properly check for user input, allowing unauthorized users to change the status of tasks that do not belong to them.

Detected in:

Zephyr Project Manager open vulnerable versions: >= * <= 3.3.100

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.