PT-2024-27588 · WordPress · Sp Project & Document Manager

·

CVE-2024-3748

·

Published

2024-05-15

·

Updated

2025-05-15

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SP Project & Document Manager WordPress plugin versions 4.71 and earlier
Description The issue is related to missing validation in the upload function of the plugin, allowing a user to manipulate the user id variable to make it appear that a file was uploaded by another user. This can lead to unauthorized access.
Recommendations For SP Project & Document Manager WordPress plugin versions 4.71 and earlier: Update the plugin to the latest patched version immediately. As a temporary workaround, consider restricting access to the upload function to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2024-3748

Affected Products

Sp Project & Document Manager