CVE-2024-3749
15.05.2024, 06:15
The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files belonging to another userEnginsight
Vendor | Product | Version |
---|---|---|
smartypantsplugins | sp_project_\&_document_manager | 𝑥 < 4.71 |
𝑥
= Vulnerable software versions