The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is due to the plugin not properly checking a users capabilities before allowing them to enable access to the plugin's settings through the update_user_access() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to grant themselves full access to the plugin's settings.
References
Configurations
History
11 Feb 2025, 20:13
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
First Time |
Zephyr-one
Zephyr-one zephyr Project Manager |
|
CPE | cpe:2.3:a:zephyr-one:zephyr_project_manager:*:*:*:*:*:wordpress:*:* | |
CWE | CWE-863 | |
References | () https://plugins.trac.wordpress.org/browser/zephyr-project-manager/trunk/includes/Base/AjaxHandler.php?rev=3111536#L2464 - Product | |
References | () https://plugins.trac.wordpress.org/changeset/3134404/ - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/b9ef344d-cd56-43f9-b185-de83a92800de?source=cve - Third Party Advisory |
15 Aug 2024, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-08-15 03:15
Updated : 2025-02-11 20:13
NVD link : CVE-2024-7624
Mitre link : CVE-2024-7624
CVE.ORG link : CVE-2024-7624
JSON object : View
Products Affected
zephyr-one
- zephyr_project_manager