The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files belonging to another user
2024-05-15T06:15:14.040
2025-05-15T13:47:41.420
Analyzed
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | smartypantsplugins | sp_project_\&_document_manager | < 4.71 | Yes |