📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global general Technology/AI Services LOW 1h Global vulnerability Information Technology CRITICAL 4h Global vulnerability Information Technology CRITICAL 5h Global vulnerability Software and Technology HIGH 5h Global vulnerability Software and Cloud Services CRITICAL 5h Global phishing Artificial Intelligence and Email Security HIGH 6h Global phishing Email and Communications CRITICAL 7h Global vulnerability Enterprise Software / E-commerce CRITICAL 7h Global supply_chain Software Development and Technology CRITICAL 7h Global vulnerability Information Technology HIGH 8h Global general Technology/AI Services LOW 1h Global vulnerability Information Technology CRITICAL 4h Global vulnerability Information Technology CRITICAL 5h Global vulnerability Software and Technology HIGH 5h Global vulnerability Software and Cloud Services CRITICAL 5h Global phishing Artificial Intelligence and Email Security HIGH 6h Global phishing Email and Communications CRITICAL 7h Global vulnerability Enterprise Software / E-commerce CRITICAL 7h Global supply_chain Software Development and Technology CRITICAL 7h Global vulnerability Information Technology HIGH 8h Global general Technology/AI Services LOW 1h Global vulnerability Information Technology CRITICAL 4h Global vulnerability Information Technology CRITICAL 5h Global vulnerability Software and Technology HIGH 5h Global vulnerability Software and Cloud Services CRITICAL 5h Global phishing Artificial Intelligence and Email Security HIGH 6h Global phishing Email and Communications CRITICAL 7h Global vulnerability Enterprise Software / E-commerce CRITICAL 7h Global supply_chain Software Development and Technology CRITICAL 7h Global vulnerability Information Technology HIGH 8h
Vulnerabilities

CVE-2026-10737

High
CWE-862 — Weakness Type
Published: Jun 4, 2026  ·  Modified: Jun 10, 2026  ·  Source: NVD
CVSS v3
7.5
🔗 NVD Official
📄 Description (English)

The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the view_file function in all versions up to, and including, 4.71. This makes it possible for unauthenticated attackers to read file metadata and obtain download links for arbitrary files stored inside project folders on the server, which can contain sensitive information. The authorization gate uses a negated nonce check OR-chained with permission checks, meaning a missing or invalid nonce causes the entire condition to evaluate to true and bypass all preceding capability and ownership checks. The secondary fallback check only denies access for root-level files (pid == 0), leaving all files stored inside project folders fully exposed to unauthenticated users who supply only a valid file ID in a POST request to admin-ajax.php.

🤖 AI Executive Summary

CVE-2026-10737 is a critical authorization bypass vulnerability in the SP Project & Document Manager WordPress plugin (versions ≤4.71) that allows unauthenticated attackers to access arbitrary file metadata and download links through a flawed nonce validation logic. The vulnerability affects all files stored in project folders, potentially exposing sensitive business documents, contracts, and confidential data. With no patch currently available and no exploit publicly disclosed, organizations using this plugin face immediate risk of data exfiltration.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Jun 8, 2026 07:17
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability poses significant risk to Saudi organizations across multiple sectors: (1) Banking & Financial Services (SAMA-regulated entities) - exposure of customer financial documents, loan applications, and transaction records; (2) Government Agencies (NCA oversight) - potential disclosure of classified procurement documents and administrative records; (3) Healthcare Providers - HIPAA-equivalent patient records and medical documentation; (4) Energy Sector (ARAMCO, SABIC) - technical specifications, project plans, and operational documents; (5) Telecommunications (STC, Mobily) - customer contracts and network infrastructure documentation; (6) Real Estate & Construction - architectural plans, contracts, and project specifications. The vulnerability is particularly dangerous for Saudi organizations as many use WordPress-based document management systems for internal collaboration and client-facing portals.
🏢 Affected Saudi Sectors
Banking & Financial Services Government & Public Administration Healthcare & Medical Services Energy & Utilities Telecommunications Real Estate & Construction Legal Services Education Retail & E-commerce
⚖️ Saudi Risk Score (AI)
8.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Disable the SP Project & Document Manager plugin immediately until a patch is released
2. If disabling is not possible, restrict access to admin-ajax.php to authenticated users only via .htaccess or WAF rules
3. Audit server logs for POST requests to admin-ajax.php with action=view_file parameters from unauthenticated sources
4. Identify and secure all files previously accessible through this vulnerability

DETECTION RULES:
- Monitor POST requests to /wp-admin/admin-ajax.php containing 'action=view_file' parameter
- Alert on requests with missing or invalid nonce values combined with file ID parameters
- Flag any unauthenticated access attempts to document retrieval functions
- Review access logs for patterns of sequential file ID enumeration

COMPENSATING CONTROLS:
1. Implement Web Application Firewall (WAF) rules to block admin-ajax.php POST requests from non-authenticated sessions
2. Apply strict file permissions (644 or more restrictive) on project folders
3. Move sensitive project folders outside web root if possible
4. Implement additional authentication layer via reverse proxy or API gateway
5. Enable comprehensive logging and SIEM monitoring for document access attempts

PATCHING GUIDANCE:
- Monitor plugin repository for security update (currently unavailable)
- Consider alternative document management solutions with proper authorization controls
- If update becomes available, test in staging environment before production deployment
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. قم بتعطيل إضافة SP Project & Document Manager فوراً حتى يتم إصدار تصحيح
2. إذا كان التعطيل غير ممكن، قيد الوصول إلى admin-ajax.php للمستخدمين المصرحين فقط عبر .htaccess أو قواعد WAF
3. قم بفحص سجلات الخادم للبحث عن طلبات POST إلى admin-ajax.php مع معاملات view_file من مصادر غير مصرحة
4. حدد وأمّن جميع الملفات التي كانت يمكن الوصول إليها من خلال هذه الثغرة

قواعد الكشف:
- راقب طلبات POST إلى /wp-admin/admin-ajax.php التي تحتوي على معامل 'action=view_file'
- أصدر تنبيهات للطلبات التي تحتوي على قيم nonce مفقودة أو غير صحيحة مع معاملات معرف الملف
- علّم أي محاولات وصول غير مصرحة لوظائف استرجاع المستندات
- راجع سجلات الوصول للبحث عن أنماط تعداد معرف الملف المتسلسل

الضوابط البديلة:
1. تطبيق قواعد جدار الحماية (WAF) لحجب طلبات POST إلى admin-ajax.php من جلسات غير مصرحة
2. تطبيق أذونات ملفات صارمة (644 أو أكثر تقييداً) على مجلدات المشاريع
3. نقل مجلدات المشاريع الحساسة خارج جذر الويب إن أمكن
4. تطبيق طبقة مصادقة إضافية عبر reverse proxy أو API gateway
5. تفعيل السجلات الشاملة ومراقبة SIEM لمحاولات الوصول إلى المستندات

إرشادات التصحيح:
- راقب مستودع الإضافات للحصول على تحديث أمني (غير متاح حالياً)
- فكر في حلول إدارة المستندات البديلة مع ضوابط تفويض مناسبة
- إذا أصبح التحديث متاحاً، اختبره في بيئة التجريب قبل نشره في الإنتاج
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.6.1.1 - Information Security Policies and Procedures ECC 2024 A.6.2.1 - User Access Management ECC 2024 A.6.2.2 - Privileged Access Rights ECC 2024 A.7.1.1 - Physical and Logical Access Controls ECC 2024 A.8.2.1 - Classification of Information ECC 2024 A.8.2.3 - Handling of Assets ECC 2024 A.12.4.1 - Event Logging ECC 2024 A.12.4.3 - Protection of Log Information
🔵 SAMA CSF
SAMA CSF Governance - Policy and Risk Management SAMA CSF Identify - Asset Management and Access Control SAMA CSF Protect - Access Control and Authentication SAMA CSF Detect - Monitoring and Logging SAMA CSF Respond - Incident Response Procedures
🟡 ISO 27001:2022
ISO 27001:2022 A.5.3 - Segregation of Duties ISO 27001:2022 A.8.1.1 - Screening ISO 27001:2022 A.8.2.1 - User Registration and De-registration ISO 27001:2022 A.8.2.3 - Management of Privileged Access Rights ISO 27001:2022 A.8.3.1 - User Access Provisioning ISO 27001:2022 A.8.3.2 - Privileged Access Rights ISO 27001:2022 A.8.3.4 - Review of User Access Rights ISO 27001:2022 A.9.2.1 - User Endpoint Devices ISO 27001:2022 A.12.4.1 - Event Logging
🟣 PCI DSS v4.0.1
PCI DSS 3.2.1 - Render PAN Unreadable PCI DSS 6.5.1 - Injection Flaws PCI DSS 6.5.10 - Broken Authentication PCI DSS 7.1 - Limit Access to System Components PCI DSS 7.2 - Ensure User Identity is Properly Identified PCI DSS 10.2 - Implement Automated Audit Trails
📊 CVSS Score
7.5
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityN — None / Network
AvailabilityN — None / Network
📋 Quick Facts
Severity High
CVSS Score7.5
CWECWE-862
EPSS0.07%
Exploit No
Patch ✗ No
Published 2026-06-04
Source Feed nvd
🇸🇦 Saudi Risk Score
8.2
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
CWE-862
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.