Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 18 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Smartypantsplugins
Smartypantsplugins sp Project & Document Manager Wordpress Wordpress wordpress |
|
| Vendors & Products |
Smartypantsplugins
Smartypantsplugins sp Project & Document Manager Wordpress Wordpress wordpress |
Tue, 17 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 17 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing Authorization vulnerability in Smartypants SP Project & Document Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SP Project & Document Manager: from n/a through 4.70. | |
| Title | WordPress SP Project & Document Manager plugin <= 4.70 - Broken Access Control to XSS vulnerability | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-04-28T16:09:28.508Z
Reserved: 2024-03-28T06:58:24.005Z
Link: CVE-2024-31118
Updated: 2026-02-17T15:22:39.904Z
Status : Deferred
Published: 2026-02-17T15:16:05.817
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-31118
No data.
OpenCVE Enrichment
Updated: 2026-02-18T10:43:48Z