CVE-2025-32526: WordPress Zephyr Project Manager plugin <= 3.3.101 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows Reflected XSS.This issue affects Zephyr Project Manager: from n/a through <= 3.3.101.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32526?
CVE-2025-32526 has a high severity rating due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2025-32526?
To fix CVE-2025-32526, upgrade the Zephyr Project Manager to version 3.3.102 or later as soon as possible.
What specific vulnerability does CVE-2025-32526 address?
CVE-2025-32526 addresses improper neutralization of input during web page generation leading to reflected cross-site scripting.
Which versions of Zephyr Project Manager are affected by CVE-2025-32526?
CVE-2025-32526 affects Zephyr Project Manager versions from n/a through 3.3.101.
Is there a workaround for CVE-2025-32526 if I cannot immediately update?
A temporary workaround for CVE-2025-32526 may involve sanitizing user inputs, but it is advisable to apply the patch as soon as possible.