Input validation vulnerability in Zephyr Project Manager 3.3.93

The Zephyr Project Manager plugin for WordPress is vulnerable to an attack called Cross-Site Request Forgery. This means that in versions up to 3.3.93, a malicious person may be able to delete all plugin data without needing to log in. This is because the security measure known as “nonce validation” is not present or is incorrect in the ~/templates/settings.php file. For an attack to be successful, a website administrator must be tricked into performing an action, such as clicking on a link.

Detected in:

Zephyr Project Manager open vulnerable versions: >= * <= 3.3.93

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.