Unauthorized Access in SP Project & Document Manager Plugin for WordPress
CVE-2026-10737

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
4 June 2026

What is CVE-2026-10737?

The SP Project & Document Manager plugin for WordPress has a vulnerability that allows unauthorized users to access sensitive file metadata due to a lack of a proper capability check on the 'view_file' function. This vulnerability affects all versions up to and including 4.71. Attackers can exploit this flaw to retrieve download links for files stored in project folders by submitting a valid file ID through a POST request to admin-ajax.php. The design flaw includes a negated nonce check, allowing the condition to bypass ownership controls if the nonce is missing or invalid. Only root-level files are protected, leaving other files unguarded and accessible to unauthenticated users.

Affected Version(s)

SP Project & Document Manager 0 <= 4.71

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

NamDang
.