[High] CVE-2026-10737 – The SP Project & Document Manager plugin for WordPress is vulnerable to unauthor...
High CVE-2026-10737 The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the view_file function in all versions up to, and including, 4.71. This makes it possible for unauthenticated attackers to read file metadata and...