CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zealousweb 1Generate Pdf Using Contact Form 7 Apr 8, 2026 Jul 9, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 4.1.2. This is due to missing nonce validation and the plu...Show more |
1Zealousweb 1Generate Pdf Using Contact Form 7 Apr 8, 2026 Jul 9, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 4.1.2. This is due to missing nonce validation and missing...Show more |
1Zealousweb 1Generate Pdf Using Contact Form 7 Apr 23, 2026 Jul 9, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Unrestricted Upload of File with Dangerous Type vulnerability in ZealousWeb Generate PDF using Contact Form 7 generate-pdf-using-contact-form-7.This issue affects Generate PDF using Contact Form 7: from n/a through <= 4....Show more |
1Zealousweb 1Generate Pdf Using Contact Form 7 May 22, 2025 Sep 26, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The Generate PDF WordPress plugin before 3.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disa...Show more |