plugin

3Dprint Lite Vulnerabilities

19 known security issues reported for the 3Dprint Lite WordPress plugin. Most recent disclosed Apr 7, 2025.

1 critical 6 medium

Running 3Dprint Lite on your site? Check whether your installed version is affected.

Scan your site free

3DPrint Lite <=2.1.3.6 - Authenticated (Admin+) SQL Injection via 'infill_text'

medium

The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'infill_text' parameter in all versions up to, and including, 2.1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attacke...

CVSS:
4.9
Affected:
up to 2.1.3.6
Fixed in:
2.1.3.7
Disclosed:
Apr 7, 2025

CVE-2025-3427 on NVD →

3DPrint Lite <=2.1.3.6 - Authenticated (Admin+) SQL Injection via 'material_text'

medium

The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'material_text' parameter in all versions up to, and including, 2.1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attac...

CVSS:
4.9
Affected:
up to 2.1.3.6
Fixed in:
2.1.3.7
Disclosed:
Apr 7, 2025

CVE-2025-3429 on NVD →

3DPrint Lite <=2.1.3.6 - Authenticated (Admin+) SQL Injection via 'printer_text'

medium

The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'printer_text' parameter in all versions up to, and including, 2.1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attack...

CVSS:
4.9
Affected:
up to 2.1.3.6
Fixed in:
2.1.3.7
Disclosed:
Apr 7, 2025

CVE-2025-3430 on NVD →

3DPrint Lite <=2.1.3.6 - Authenticated (Admin+) SQL Injection via 'coating_text'

medium

The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'coating_text' parameter in all versions up to, and including, 2.1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attack...

CVSS:
4.9
Affected:
up to 2.1.3.6
Fixed in:
2.1.3.7
Disclosed:
Apr 7, 2025

CVE-2025-3428 on NVD →

3DPrint Lite <= 2.1.3.5 - Cross-Site Request Forgery

medium

The 3DPrint Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.3.5. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site admini...

CVSS:
4.3
Affected:
up to 2.1.3.5
Fixed in:
2.1.3.6
Disclosed:
Mar 27, 2025

CVE-2025-30865 on NVD →

3DPrint Lite [3dprint-lite] < 2.1.3.6

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in fuzzoid 3DPrint Lite allows Cross Site Request Forgery. This issue affects 3DPrint Lite: from n/a through 2.1.3.5.

Affected:
up to 2.1.3.6
Fixed in:
2.1.3.6
Disclosed:
Mar 27, 2025

CVE-2025-30865 on NVD →

3DPrint Lite [3dprint-lite] < 2.1

unknown

[en] The 3DPrint Lite WordPress plugin before 2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

Affected:
up to 2.1
Fixed in:
2.1
Disclosed:
Dec 6, 2024

CVE-2024-10480 on NVD →

3DPrint Lite <= 2.0.9.9 - Cross-Site Request Forgery to Settings Update

medium

The 3DPrint Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9.9. This is due to missing or incorrect nonce validation on the 'p3dlite_settings' action. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged reques...

CVSS:
4.3
Affected:
up to 2.0.9.9
Fixed in:
2.1
Disclosed:
Nov 15, 2024

CVE-2024-10480 on NVD →

3DPrint Lite [3dprint-lite] < 1.9.1.5

unknown

[en] The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJAX action , allowing unauthenticated users to upload arbitrary file to the web server. However, there is a .htaccess, preventing the file to be accessed on Web server...

Affected:
up to 1.9.1.5
Fixed in:
1.9.1.5
Disclosed:
Feb 5, 2024

CVE-2021-4436 on NVD →

3DPrint Lite [3dprint-lite] < 1.9.1.6

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress 3DPrint Lite plugin (versions <= 1.9.1.5).

Affected:
up to 1.9.1.6
Fixed in:
1.9.1.6
Disclosed:
Oct 11, 2021

3DPrint Lite < 1.9.1.5 - Arbitrary File Upload

critical

The 3DPrint Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the p3dlite_handle_upload function in versions before 1.9.1.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execu...

CVSS:
9.8
Affected:
up to 1.9.1.5
Fixed in:
1.9.1.5
Disclosed:
Sep 23, 2021

CVE-2021-4436 on NVD →

3DPrint Lite [3dprint-lite] < 1.9.1.5

unknown

Unauthenticated Arbitrary File Upload vulnerability discovered by Spacehen in WordPress 3DPrint Lite plugin (versions <= 1.9.1.4).

Affected:
up to 1.9.1.5
Fixed in:
1.9.1.5
Disclosed:
Sep 23, 2021

3DPrint Lite [3dprint-lite] < 1.9.1.5

unknown

The 3DPrint Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the p3dlite_handle_upload function in versions before 1.9.1.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execu...

Affected:
up to 1.9.1.5
Fixed in:
1.9.1.5
Disclosed:
Sep 23, 2021

3DPrint Lite [3dprint-lite] < 1.9.1.5

unknown

The p3dlite_handle_upload AJAX action of the plugin does not have any authorisation and does not check the uploaded file, allowing unauthenticated users to upload arbitrary file to the web server. However, there is a .htaccess, preventing the file to be accessed on Web servers such as Apache.

Affected:
up to 1.9.1.5
Fixed in:
1.9.1.5

3DPrint Lite [3dprint-lite] < 1.9.1.6

unknown

The plugin does not sanitise and escape some user input before outputting it back in attributes, leading to Reflected Cross-Site Scripting issues

Affected:
up to 1.9.1.6
Fixed in:
1.9.1.6

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database