CVE-2021-4225
The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that on Windows servers, the security checks in place were insufficient, enabling bad actors to potentially upload backdoors on vulnerable sites.
- Affected products
- Sp Project & Document Manager
- Smartypantsplugins Sp Project \& Document Manager
- < 4.24
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 1.7% (75th percentile)
- Weakness
- CWE-434
- NVD status
- Modified
- Published
- 2022-04-25
CVE-2021-4225 at NVD
No indexed exploits for CVE-2021-4225 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2021-4225 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.