The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files belonging to another user
[
{
"vendor": "Unknown",
"product": "SP Project & Document Manager",
"versions": [
{
"status": "affected",
"versionType": "semver",
"version": "0",
"lessThanOrEqual": "4.71"
}
],
"defaultStatus": "affected"
}
]