Input validation vulnerability in SP Project & Document Manager 2.6.1.3

The SP Projects & Document Manager plugin for WordPress may have a security vulnerability in versions up to and including 2.6.0.0. The vulnerability could allow attackers to upload any type of file to the affected site’s server, which could lead to remote code execution. This is caused by a lack of validation of file types on the cdm_upload_file() function.

Detected in:

SP Project & Document Manager open vulnerable versions: >= * <= 2.6.1.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.