Junglewise Threat Intelligence

CVE-2026-76931: Zephyr Project Manager stored cross-site scripting in message parameter

CVE-2026-76931 · Severity: medium · CVSS 6.4 · Published 2026-09-08

Vendors: Zephyr Project.

Executive brief

Zephyr Project Manager is a WordPress plugin used to manage projects and tasks. The plugin fails to properly sanitize user input in the message parameter, allowing authenticated users with Custom-level access or higher to inject malicious scripts that execute when other users view affected pages. This can lead to session hijacking, credential theft, or defacement of project pages.

Technical details

The vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the Zephyr Project Manager WordPress plugin affecting versions up to and including 3.3.205. The root cause is insufficient input sanitization and output escaping of the 'message' parameter in the plugin's code (likely in AjaxHandler.php and/or Projects.php based on referenced files). The vulnerability requires authentication with Custom-level access or above and is only exploitable when the 'Directly link to project' plugin setting is disabled. An authenticated attacker can inject arbitrary JavaScript that persists in the database and executes in the browsers of other users who access the affected page, enabling session hijacking, credential theft, or malicious actions performed on behalf of other users.

Affected products

  • Zephyr Project Zephyr Project Manager up to and including 3.3.205

Timeline

  • 2026-09-08: disclosed

References