Access violation vulnerability in SP Project & Document Manager 4.70

The SP Project & Document Manager plugin for WordPress has a security issue that allows unauthorized changes to be made to data. This happens because there is no check to make sure the user has the right permissions when using the cdm_save_category function. This vulnerability exists in all versions up to and including 4.70. This means that people who are logged in and have at least subscriber-level access can change the names of folders that they don’t own.

Detected in:

SP Project & Document Manager open vulnerable versions: >= * <= 4.70

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.