CVE-2024-6316
- EPSS 2.03%
- Published 09.07.2024 08:15:12
- Last modified 07.03.2025 16:48:11
The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 4.0.6. This is due to missing nonce validation and missing file type validation in the '...
CVE-2024-6317
- EPSS 6.31%
- Published 09.07.2024 08:15:12
- Last modified 07.03.2025 16:48:11
The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 4.0.6. This is due to missing nonce validation and the plugin not properly validating a ...
CVE-2024-37555
- EPSS 0.36%
- Published 09.07.2024 08:15:10
- Last modified 21.11.2024 09:24:04
Unrestricted Upload of File with Dangerous Type vulnerability in ZealousWeb Generate PDF using Contact Form 7.This issue affects Generate PDF using Contact Form 7: from n/a through 4.0.6.
CVE-2022-3070
- EPSS 0.42%
- Published 26.09.2022 13:15:10
- Last modified 22.05.2025 14:16:00
The Generate PDF WordPress plugin before 3.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.