Missing Authorization Vulnerability in Smartypants SP Project & Document Manager
CVE-2024-31118
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 February 2026
What is CVE-2024-31118?
A missing authorization vulnerability has been identified in the Smartypants SP Project & Document Manager, which allows unauthorized access due to incorrectly configured access control security levels. This flaw can potentially lead to security breaches, enabling attackers to exploit weaknesses that compromise sensitive project and document management functions. Users are urged to take immediate action to secure their installations to prevent unauthorized data access.
Affected Version(s)
SP Project & Document Manager <= 4.70