article2pdf <= 0.27 - Denial of Service
high
A disk space or quota exhaustion issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugin 0.24, 0.25, 0.26, 0.27. Visiting PDF generation link but not following the redirect will leave behind a PDF file on disk which will never be deleted by the plug-in.
- CVSS:
- 7.5
- Affected:
- 0.24 – 0.24, 0.25 – 0.25, 0.26 – 0.26, 0.27 – 0.27
- Fix:
- No patched version reported
- Disclosed:
- Mar 29, 2019
CVE-2019-1000031 on NVD →
article2pdf [article2pdf] < 0.28 (closed)
unknown
Multiple vulnerabilities found by Christian Lerrahn in WordPress article2pdf plugin (versions <=0.27).
- Affected:
- up to 0.28
- Fixed in:
- 0.28
- Disclosed:
- Mar 28, 2019
article2pdf [article2pdf] >= 0.24 - <= 0.27 (unfixed + closed)
unknown
[en] A disk space or quota exhaustion issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugin 0.24, 0.25, 0.26, 0.27. Visiting PDF generation link but not following the redirect will leave behind a PDF file on disk which will never be deleted by the plug-in.
- Affected:
- 0.24 – 0.27
- Fix:
- No patched version reported
- Disclosed:
- Mar 27, 2019
CVE-2019-1000031 on NVD →
article2pdf [article2pdf] >= 0.24 - <= 0.27 (unfixed + closed)
unknown
[en] An Information Disclosure / Data Modification issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugin 0.24, 0.25, 0.26, 0.27. A URL can be constructed which allows overriding the PDF file's path leading to any PDF whose path is known and which is readable to the web server can be downloaded. Th...
- Affected:
- 0.24 – 0.27
- Fix:
- No patched version reported
- Disclosed:
- Mar 27, 2019
CVE-2019-1010257 on NVD →
article2pdf 0.24 - 0.27 - Information Disclosure
critical
An Information Disclosure / Data Modification issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugin 0.24, 0.25, 0.26, 0.27. A URL can be constructed which allows overriding the PDF file's path leading to any PDF whose path is known and which is readable to the web server can be downloaded. The fil...
- CVSS:
- 9.1
- Affected:
- 0.24 – 0.24, 0.25 – 0.25, 0.26 – 0.26, 0.27 – 0.27
- Fix:
- No patched version reported
- Disclosed:
- Mar 26, 2019
CVE-2019-1010257 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database