Limited Privilege Escalation Vulnerability in Zephyr Project Manager for WordPress
CVE-2024-7624
8.1HIGH
Summary
The Zephyr Project Manager plugin for WordPress is susceptible to a privilege escalation vulnerability across all versions up to and including 3.3.101. This flaw arises from the plugin's failure to validate user capabilities correctly within the update_user_access() function. As a result, authenticated users with subscriber-level access or higher can manipulate their permissions, enabling unrestricted access to the plugin's settings. This could allow them to alter configurations and potentially compromise the integrity of the WordPress installation.
Affected Version(s)
Zephyr Project Manager * <= 3.3.101
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
wesley