WordPress SP Project & Document Manager plugin <= 4.59 - Reflected Cross-Site Scripting (XSS) vulnerability
No known patch is available for this vulnerability.
The affected plugin has been removed from the WordPress.org directory (reason: Security Issue), and no patched version is being distributed through the official directory. If you have the affected software installed, you should uninstall or replace it rather than wait for an update.
Description
Reflected XSS in SP Project & Document Manager plugin <= 4.59 for WordPress; plugin removed from directory, no fix available.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Reflected XSS in SP Project & Document Manager plugin <= 4.59 for WordPress; plugin removed from directory, no fix available.
Vulnerability
The SP Project & Document Manager plugin (slug: sp-client-document-manager) for WordPress versions up to and including 4.59 contains a reflected Cross-Site Scripting (XSS) vulnerability. An attacker can inject arbitrary JavaScript via a crafted URL parameter that is not properly sanitized before being reflected in the response. No authentication or special configuration is required to trigger the vulnerability; the user only needs to visit a maliciously crafted link.
Exploitation
An attacker sends a crafted link to a logged-in WordPress user. When the user clicks the link, the injected JavaScript executes in the context of the victim's browser session with the WordPress site. The attack requires no special privileges or network position; the attacker must simply trick the user into clicking the link.
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser. This can lead to theft of session cookies, redirection to malicious sites, defacement of the page, or other actions within the context of the affected WordPress site and user's session.
Mitigation
The plugin has been closed and removed from the WordPress.org plugin directory as of March 7, 2024, due to a security issue [1]. No patched version is available through the official directory. Users who have this plugin installed should uninstall it immediately and consider alternative solutions. There is no known workaround.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=4.59
- smartypants/SP Project & Document Manager (WordPress plugin)v5Range: <= 4.59
Patches
0sp-client-document-managerThis plugin has been removed from the WordPress.org directory on 2024-03-07 (reason: Security Issue). No patched version is being distributed through the official directory. Users who have it installed should uninstall it.
Source: api.wordpress.org · directory page
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.