CVE-2024-6536: Zephyr Project Manager < 3.3.99 - Editor+ XSS
The Zephyr Project Manager WordPress plugin before 3.3.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors and admins to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6536?
CVE-2024-6536 is considered a critical vulnerability due to its potential for enabling Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-6536?
To fix CVE-2024-6536, update the Zephyr Project Manager plugin to version 3.3.99 or later.
Who is affected by CVE-2024-6536?
CVE-2024-6536 affects users of the Zephyr Project Manager plugin prior to version 3.3.99, specifically those with high privileges like editors and admins.
What kind of attack can CVE-2024-6536 enable?
CVE-2024-6536 can enable Stored Cross-Site Scripting attacks, allowing attackers to inject malicious scripts.
Is CVE-2024-6536 exploitable without unfiltered_html capability?
Yes, CVE-2024-6536 can be exploited even when the unfiltered_html capability is disallowed for users.