Smartypants SP Project & Document Manager
cpe:2.3:a:smartypantsplugins:sp_project_&_document_manager:*:*:*:*:wordpress:*:*
- <= 4.70
A missing authorization vulnerability has been identified in the Smartypants SP Project & Document Manager plugin for WordPress, affecting versions through 4.70. This vulnerability arises from incorrectly configured access control security levels, which can be exploited to perform actions without the necessary privileges.
Exploitation of this vulnerability could lead to broken access control, allowing users to perform actions or access resources that should be restricted.
Users of the Smartypants SP Project & Document Manager plugin are advised to update to a version later than 4.70. For those seeking immediate protection, Patchstack offers a mitigation rule that can be applied until an official fix is available.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.