← back
CVE-2022-1551

SP Project & Document Manager < 4.58 - Sensitive File Disclosure

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 0.9%
exploitation probability
0.9%top 43% of all CVEs
observed exploitation
nono source reports it
The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.