Description
The Zephyr Project Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.203 via the `file` parameter. This makes it possible for authenticated attackers, with Custom-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. On a servers that have `allow_url_fopen` enabled, this issue allows for Server-Side Request Forgery
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
* (semver)
Timeline
| 2025-10-21: | Discovered |
| 2025-10-29: | Vendor Notified |
| 2025-12-16: | Disclosed |
Credits
M Indra Purnama
References
www.wordfence.com/...-d61a-4969-a5c0-d2d709fb56d0?source=cve
plugins.trac.wordpress.org/.../includes/Base/AjaxHandler.php
plugins.trac.wordpress.org/...unk/includes/Core/Projects.php
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.