WordPress Plugin Vulnerabilities

SP Project & Document Manager <= 4.71 - Subscriber+ File Download via IDOR

Description

The plugin lacks proper access controllers and allows a logged in user to view and download files belonging to another user

Proof of Concept

Affects Plugins

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
fewwords
Submitter
fewwords
Verified
Yes

Timeline

Publicly Published
2024-04-24 (about 1 year ago)
Added
2024-04-24 (about 1 year ago)
Last Updated
2024-04-24 (about 1 year ago)

Other