CVE-2022-1551

MEDIUM

SP Project & Document Manager <4.58 - Info Disclosure

Title source: llm
STIX 2.1

Description

The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.

Scores

CVSS v3 6.5
EPSS 0.0044
EPSS Percentile 63.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-425
Status published
Products (1)
smartypantsplugins/sp_project_\&_document_manager < 4.58
Published Jul 25, 2022
Tracked Since Feb 18, 2026