CVE-2025-54714: WordPress Zephyr Project Manager Plugin <= 3.3.201 - Broken Access Control Vulnerability
Missing Authorization vulnerability in Dylan James Zephyr Project Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Zephyr Project Manager: from n/a through 3.3.201.
Other sources
Missing Authorization vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zephyr Project Manager: from n/a through <= 3.3.201.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54714?
CVE-2025-54714 is classified as a high-severity vulnerability due to its potential to allow unauthorized access.
How do I fix CVE-2025-54714?
To fix CVE-2025-54714, ensure that access control security levels are correctly configured in Zephyr Project Manager.
Which versions of Zephyr Project Manager are affected by CVE-2025-54714?
CVE-2025-54714 affects versions of Zephyr Project Manager up to and including 3.3.201.
Can CVE-2025-54714 be exploited remotely?
Yes, CVE-2025-54714 can be exploited remotely because it involves incorrectly configured access controls.
What products are linked to CVE-2025-54714?
CVE-2025-54714 is linked to the Dylan James Zephyr Project Manager and the WordPress Zephyr Project Manager Plugin.