Pricing
WordPress securityInstantly fix and mitigate vulnerabilitiesPlugin auditingPaid auditing for WordPress vendorsManaged VDPStart a security program for your pluginsBug BountyJoin the community and earn bountiesEnterprise APIAt scale monitoring and vPatching for hostsVulnerability databaseThe latest WordPress security intelligence
Login Start trial
Plugin Icon

SP Project & Document Manager

N/A

Developer

N/A

Latest version

N/A

Installations

N/A

Last updated

WordPress Plugin
No VDP
Claim ownership
Report vulnerability
    Vulnerabilities

Vulnerability history

6 present
11 fixed
9 Mitigation rules
  • Directory Traversal vulnerability
    <= 4.71
    Jun 21, 2024
  • Data Update and File Download via IDOR vulnerability
    <= 4.71
    May 15, 2024
  • Authenticated (Subscriber+) Arbitrary Folder Name Update vulnerability
    <= 4.70
    May 15, 2024
  • Broken Access Control vulnerability
    <= 4.69
    Apr 29, 2024
  • Auth. SQL Injection vulnerability
    <= 4.71
    Apr 16, 2024
  • Broken Access Control to XSS vulnerability
    <= 4.70
    Mar 29, 2024
  • Contributor+ SQL Injection vulnerability
    <= 4.69
    Feb 2, 2024
  • Auth. Insecure Direct Object Reference vulnerability
    <= 4.67
    Jun 30, 2023
  • SQL Injection
    <= 4.67
    Jun 30, 2023
  • Cross Site Scripting (XSS) vulnerability
    <= 4.67
    Jun 30, 2023
  • Reflected Cross-Site Scripting (XSS) vulnerability
    <= 4.59
    Aug 10, 2022
  • Sensitive File Disclosure vulnerability
    <= 4.57
    Jun 29, 2022
  • Attribute-based Reflected Cross-Site Scripting (XSS) vulnerability
    <= 4.25
    Aug 16, 2021
  • Authenticated Shell Upload vulnerability
    <= 4.21
    May 25, 2021
  • Multiple Vulnerabilities
    <= 2.5.9.5
    Mar 7, 2016
  • Blind SQL Injection
    <= 2.5.3
    Mar 31, 2015
  • SQL Injection
    <= 2.4.1
    Nov 21, 2014

Vulnerability mitigation

  • Pricing
  • Application security (SCA)
  • RapidMitigate New
  • Threat Intelligence (API)
  • Documentation
  • VS Monarx
  • VS Imunify360
  • VS Wordfence
  • Log in

Code security

  • Managed VDP New
  • Active VDP directory
  • Security auditing
  • Compliance (CRA) New
  • Log in New

Bug bounty

  • Bug bounty
  • Leaderboard
  • Guidelines
  • Learn New
  • Report
  • Discord
  • Log in New

Use cases

  • Web developers
  • Webhosts New
  • Software vendors
  • WordPress
  • WooCommerce

Resources

  • Vulnerability database
  • Whitepaper 2025 New
  • Articles
  • Case studies New
  • Webinars New
  • Vulnerability statistics

Patchstack

  • About
  • Careers
  • Merch store
  • Media kit
  • LinkedIn
  • Facebook
  • X
© 2025 Patchstack
DPA
Privacy Policy
Accessibility
Terms & Conditions
EU Flag