Unauthorized Access in SP Project & Document Manager Plugin for WordPress
CVE-2026-10737
7.5HIGH
What is CVE-2026-10737?
The SP Project & Document Manager plugin for WordPress has a vulnerability that allows unauthorized users to access sensitive file metadata due to a lack of a proper capability check on the 'view_file' function. This vulnerability affects all versions up to and including 4.71. Attackers can exploit this flaw to retrieve download links for files stored in project folders by submitting a valid file ID through a POST request to admin-ajax.php. The design flaw includes a negated nonce check, allowing the condition to bypass ownership controls if the nonce is missing or invalid. Only root-level files are protected, leaving other files unguarded and accessible to unauthenticated users.
Affected Version(s)
SP Project & Document Manager 0 <= 4.71