PT-2026-46111 · WordPress · Sp Project & Document Manager

·

CVE-2026-10737

·

Published

2026-06-04

·

Updated

2026-07-22

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SP Project & Document Manager versions prior to 4.72
Description Unauthorized access is possible due to a missing capability check in the view file() function. Unauthenticated attackers can read file metadata and obtain download links for arbitrary files stored within project folders on the server, potentially exposing sensitive information. The issue stems from an authorization gate that uses a negated nonce check OR-chained with permission checks; consequently, a missing or invalid nonce causes the condition to evaluate to true, bypassing capability and ownership checks. A secondary fallback check only restricts access to root-level files where pid is 0, leaving files in project folders exposed when a valid file ID is provided in a POST request to the 'admin-ajax.php' endpoint.
Recommendations Update to a version later than 4.71. As a temporary workaround, restrict access to the 'admin-ajax.php' endpoint or the view file() function to minimize the risk of exploitation.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10737

Affected Products

Sp Project & Document Manager