VYPR
Unrated severityNVD Advisory· Published Aug 22, 2022· Updated Apr 28, 2026No known patch

WordPress SP Project & Document Manager plugin <= 4.59 - Reflected Cross-Site Scripting (XSS) vulnerability

CVE-2022-34857

Description

Reflected XSS in SP Project & Document Manager plugin <= 4.59 for WordPress; plugin removed from directory, no fix available.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS in SP Project & Document Manager plugin <= 4.59 for WordPress; plugin removed from directory, no fix available.

Vulnerability

The SP Project & Document Manager plugin (slug: sp-client-document-manager) for WordPress versions up to and including 4.59 contains a reflected Cross-Site Scripting (XSS) vulnerability. An attacker can inject arbitrary JavaScript via a crafted URL parameter that is not properly sanitized before being reflected in the response. No authentication or special configuration is required to trigger the vulnerability; the user only needs to visit a maliciously crafted link.

Exploitation

An attacker sends a crafted link to a logged-in WordPress user. When the user clicks the link, the injected JavaScript executes in the context of the victim's browser session with the WordPress site. The attack requires no special privileges or network position; the attacker must simply trick the user into clicking the link.

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser. This can lead to theft of session cookies, redirection to malicious sites, defacement of the page, or other actions within the context of the affected WordPress site and user's session.

Mitigation

The plugin has been closed and removed from the WordPress.org plugin directory as of March 7, 2024, due to a security issue [1]. No patched version is available through the official directory. Users who have this plugin installed should uninstall it immediately and consider alternative solutions. There is no known workaround.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0
Plugin removedSP Project & Document Managersp-client-document-manager

This plugin has been removed from the WordPress.org directory on 2024-03-07 (reason: Security Issue). No patched version is being distributed through the official directory. Users who have it installed should uninstall it.

Source: api.wordpress.org · directory page

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.