The Zephyr Project Manager WordPress plugin before 3.2.55 does not have any authorisation as well as CSRF in all its AJAX actions, allowing unauthenticated users to call them either directly or via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also allow them to perform Stored Cross-Site Scripting attacks against logged in admins.
Conclusion & alert: CVE-2022-2839 is rated Exploit Available (53.1/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.24%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-10-08 | 0.36% | 0.24% | -0.12% |
| 2 | 2025-10-05 | 0.17% | 0.36% | +0.19% |
| 3 | 2025-06-28 | — | 0.17% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.4 | 3.1 | MEDIUM |
|
2.3 | 2.7 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
ubuntu
|
medium | CVE-2022-2839 medium priority: Ubuntu including 2 source packages (wordpress, zephyr), 26 status rows across 13 suites (bionic, focal, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): needs-triage 14, ignored 12. | https://ubuntu.com/security/CVE-2022-2839 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| zephyr-one | zephyr_project_manager | < 3.2.55 | cpe:2.3:a:zephyr-one:zephyr_project_manager:*:*:*:*:*:wordpress:*:* |
| URL | Tags |
|---|---|
| https://wpscan.com/vulnerability/82e01f95-81c2-46d8-898e-07b3b8a3f8c9 | Exploit Third Party Advisory |