Stored Cross-Site Scripting in Zephyr Project Manager for WordPress
CVE-2025-10490

4.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
26 September 2025

What is CVE-2025-10490?

The Zephyr Project Manager plugin for WordPress is prone to a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping. This flaw allows authenticated administrators to inject malicious web scripts into pages viewed by other users. It specifically impacts multi-site setups and instances where the unfiltered_html option has been disabled, potentially leading to severe consequences if exploited. It is crucial for users of this plugin to ensure they are using the latest version and to apply best practices in web security.

Affected Version(s)

Zephyr Project Manager * <= 3.3.202

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aurélien BOURDOIS
.