CVE-2024-6536

MEDIUM

Zephyr Project Manager <3.3.99 - XSS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-6536. PoCs published by apena-ba.

AI-analyzed exploit summary This PoC demonstrates a stored XSS vulnerability in the Zephyr Project Manager WordPress plugin (CVE-2024-6536) by creating a project with a malicious name containing JavaScript payload. It requires authentication and admin privileges.

Description

The Zephyr Project Manager WordPress plugin before 3.3.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors and admins to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Exploits (1)

nomisec WORKING POC 1 stars
by apena-ba · poc
https://github.com/apena-ba/CVE-2024-6536

This PoC demonstrates a stored XSS vulnerability in the Zephyr Project Manager WordPress plugin (CVE-2024-6536) by creating a project with a malicious name containing JavaScript payload. It requires authentication and admin privileges.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: Zephyr Project Manager (WordPress plugin)
Auth required
Prerequisites: Valid WordPress credentials · Zephyr Project Manager admin privileges
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Issue Tracking exploit vdb-entry technical-description
https://wpscan.com/vulnerability/ee40c1c6-4186-4b97-866c-fb0e76cedeb8/

Scores

CVSS v3 5.4
EPSS 0.0072
EPSS Percentile 49.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
dylanjkotze/zephyr_project_manager < 3.3.99
Published Jul 30, 2024
Tracked Since Feb 18, 2026