Stored Cross-Site Scripting in Zephyr Project Manager for WordPress
CVE-2025-10490
4.4MEDIUM
What is CVE-2025-10490?
The Zephyr Project Manager plugin for WordPress is prone to a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping. This flaw allows authenticated administrators to inject malicious web scripts into pages viewed by other users. It specifically impacts multi-site setups and instances where the unfiltered_html option has been disabled, potentially leading to severe consequences if exploited. It is crucial for users of this plugin to ensure they are using the latest version and to apply best practices in web security.
Affected Version(s)
Zephyr Project Manager * <= 3.3.202