WordPress Zephyr Project Manager plugin <= 3.2.40 - Reflected Cross-Site Scripting (XSS) vulnerability
Vulnerable versions
<= 3.2.40
PSID
17112aef3b5e
Classification
Cross Site Scripting (XSS)
OWASP Top 10
A7: Cross-Site Scripting (XSS)
Required privilege
Publicly disclosed
2022-05-23
Patchstack vPatch available since
09.12.2021
Details
Reflected Cross-Site Scripting (XSS) vulnerability discovered by Eduardo Estevao de Oliveira Azevedo in WordPress Zephyr Project Manager plugin (versions <= 3.2.40).
Solution
Update the WordPress Zephyr Project Manager plugin to the latest available version (at least 3.2.41).
References
CVE-2022-1822
Vulnerability details
Plugin changelog