Input validation vulnerability in SP Project & Document Manager 4.69

The SP Project & Document Manager plugin for WordPress has a security issue known as SQL Injection. This occurs when malicious code is inserted into the software, allowing attackers to access sensitive information from the database. This vulnerability exists in versions up to 4.69 of the plugin, due to the way user input is handled and the lack of proper preparation in the existing SQL query. This means that attackers with contributor-level access or higher can add their own queries to extract data from the database.

Detected in:

SP Project & Document Manager open vulnerable versions: >= * <= 4.69

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.