← Back

CVE-2024-7624

nvd nist
Published: Aug 15, 2024Modified: Feb 11, 2025

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.8 / Impact: 5.2
Source: security@wordfence.com (Secondary)

Description

The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is due to the plugin not properly checking a users capabilities before allowing them to enable access to the plugin's settings through the update_user_access() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to grant themselves full access to the plugin's settings.

Affected (1)

1 product
Zephyr Project Manager
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.3.102

Timeline

No history available yet.