The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.
2022-07-25T13:15:08.217
2024-11-21T06:40:57.110
Modified
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | smartypantsplugins | sp_project_\&_document_manager | < 4.58 | Yes |