Access violation vulnerability in Zephyr Project Manager 3.3.97

The Zephyr Project Manager plugin for WordPress has a security vulnerability that could potentially allow unauthorized users to gain administrator access. This vulnerability affects all versions up to 3.3.97. The issue occurs because the plugin does not properly check for changes made to user profiles through the update_user_meta function. As a result, attackers with subscriber-level access or higher could exploit this vulnerability to update their own user profiles and gain administrator privileges.

Detected in:

Zephyr Project Manager open vulnerable versions: >= * <= 3.3.97

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.