CVE-2024-3749
The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files belonging to another user
- Affected products
- Sp Project & Document Manager
- Smartypantsplugins Sp Project \& Document Manager
- < 4.71
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.5% (43th percentile)
- NVD status
- Analyzed
- Published
- 2024-05-15
CVE-2024-3749 at NVD
1 known exploit for CVE-2024-3749
Proof-of-concept code and exploit modules indexed by Sploitus