CVE-2024-6316
- EPSS 2.81%
- Veröffentlicht 09.07.2024 08:15:12
- Zuletzt bearbeitet 08.04.2026 18:22:20
The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 4.1.2. This is due to missing nonce validation and missing file type validation in the '...
CVE-2024-6317
- EPSS 6.13%
- Veröffentlicht 09.07.2024 08:15:12
- Zuletzt bearbeitet 08.04.2026 18:22:20
The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 4.1.2. This is due to missing nonce validation and the plugin not properly validating a ...
CVE-2024-37555
- EPSS 0.95%
- Veröffentlicht 09.07.2024 08:15:10
- Zuletzt bearbeitet 01.04.2026 16:17:32
Unrestricted Upload of File with Dangerous Type vulnerability in ZealousWeb Generate PDF using Contact Form 7 generate-pdf-using-contact-form-7.This issue affects Generate PDF using Contact Form 7: from n/a through <= 4.1.2.
CVE-2022-3070
- EPSS 0.3%
- Veröffentlicht 26.09.2022 13:15:10
- Zuletzt bearbeitet 22.05.2025 14:16:00
The Generate PDF WordPress plugin before 3.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.