Input validation vulnerability in SP Project & Document Manager 2.5.9.5

The SP Projects & Document Manager plugin for WordPress is vulnerable to a type of attack called SQL Injection in versions up to 2.5.9.5. This type of attack happens when user-supplied parameters are not properly escaped and existing SQL queries are not sufficiently prepared. This allows attackers to add their own SQL queries to the existing queries which can be used to access sensitive information from the database.

Detected in:

SP Project & Document Manager open vulnerable versions: >= * <= 2.5.9.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.