BSK PDF Manager <= 3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages th...
- CVSS:
- 6.4
- Affected:
- up to 3.8
- Fixed in:
- 3.8.1
- Disclosed:
- Jul 23, 2026
CVE-2026-65528 on NVD →
BSK PDF Manager <= 3.7.2 - Unauthenticated Information Exposure
medium
The BSK PDF Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.7.2. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 3.7.2
- Fixed in:
- 3.8
- Disclosed:
- Feb 22, 2026
CVE-2026-39686 on NVD →
BSK PDF Manager <= 3.7.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via SVG File Upload
medium
The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbi...
- CVSS:
- 5.5
- Affected:
- up to 3.7.1
- Fixed in:
- 3.7.2
- Disclosed:
- Dec 11, 2025
CVE-2025-4970 on NVD →
BSK PDF Manager [bsk-pdf-manager] < 3.6.1
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BannerSky.Com BSK PDF Manager allows Stored XSS.This issue affects BSK PDF Manager: from n/a through 3.6.
- Affected:
- up to 3.6.1
- Fixed in:
- 3.6.1
- Disclosed:
- Jul 20, 2024
CVE-2024-38767 on NVD →
BSK PDF Manager <= 3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a...
- CVSS:
- 6.4
- Affected:
- up to 3.6
- Fixed in:
- 3.6.1
- Disclosed:
- Jul 15, 2024
CVE-2024-38767 on NVD →
PDF.js < 4.2.67 - Arbitrary JavaScript Execution
medium
PDF.js is vulnerable to Arbitrary JavaScript Execution in versions prior to 4.2.67. This is due to a missing type check when handling fonts. This makes it possible for authenticated attackers, with contributor-level or above permissions, to execute arbitrary JavaScript if they can successfully trick a user into opening...
- CVSS:
- 6.4
- Affected:
- up to 3.6
- Fixed in:
- 3.6.1
- Disclosed:
- May 20, 2024
CVE-2024-4367 on NVD →
BSK PDF Manager [bsk-pdf-manager] < 3.6.1
unknown
[en] A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
- Affected:
- up to 3.6.1
- Fixed in:
- 3.6.1
- Disclosed:
- May 14, 2024
CVE-2024-4367 on NVD →
BSK PDF Manager [bsk-pdf-manager] < 3.1.2
unknown
Update the WordPress BSK PDF Manager plugin to the latest available version (at least 3.1.2).
JrXnm discovered and reported this SQL Injection vulnerability in WordPress BSK PDF Manager Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information....
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2
- Disclosed:
- Nov 1, 2023
BSK PDF Manager [bsk-pdf-manager] < 3.4.2
unknown
[en] The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'bsk-pdfm-category-dropdown' shortcode in versions up to, and including, 3.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with co...
- Affected:
- up to 3.4.2
- Fixed in:
- 3.4.2
- Disclosed:
- Oct 24, 2023
CVE-2023-5110 on NVD →
BSK PDF Manager <= 3.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'bsk-pdfm-category-dropdown' shortcode in versions up to, and including, 3.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contrib...
- CVSS:
- 6.4
- Affected:
- up to 3.4.1
- Fixed in:
- 3.4.2
- Disclosed:
- Oct 23, 2023
CVE-2023-5110 on NVD →
BSK PDF Manager [bsk-pdf-manager] < 1.4
unknown
Upgrade the plugin.
HauntIT Blog discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress BSK PDF Manager Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visi...
- Affected:
- up to 1.4
- Fixed in:
- 1.4
- Disclosed:
- Aug 1, 2023
BSK PDF Manager [bsk-pdf-manager] < 3.1.2
unknown
[en] The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before using them in a SQL statement, leading to a SQL injection issue
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2
- Disclosed:
- Nov 29, 2021
CVE-2021-24860 on NVD →
BSK PDF Manager <= 3.1.1 - Admin+ SQL Injection
high
The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before using them in a SQL statement, leading to a SQL injection issue
- CVSS:
- 7.2
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2
- Disclosed:
- Nov 1, 2021
CVE-2021-24860 on NVD →
BSK PDF Manager <= 1.4 - Authenticated SQL Injection
critical
Multiple SQL injection vulnerabilities in inc/bsk-pdf-dashboard.php in the BSK PDF Manager plugin 1.3.2 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) categoryid or (2) pdfid parameter to wp-admin/admin.php.
- CVSS:
- 9.9
- Affected:
- up to 1.5
- Fixed in:
- 1.5
- Disclosed:
- Aug 1, 2014
CVE-2014-4944 on NVD →
BSK PDF Manager 1.3 - 2.9 - Authenticated Stored Cross-Site Scripting
medium
The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cat_title’ parameter from versions 1.3 to 2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever...
- CVSS:
- 6.4
- Affected:
- 1.3 – 2.9
- Fixed in:
- 2.9.1
- Disclosed:
- Aug 1, 2014
BSK PDF Manager [bsk-pdf-manager] < 1.4
unknown
This plugin is prone to a cross site scripting in wp-admin/admin.php multiple parameter.
Upgrade the plugin.
- Affected:
- up to 1.4
- Fixed in:
- 1.4
- Disclosed:
- Aug 1, 2014
BSK PDF Manager [bsk-pdf-manager] < 2.9.1
unknown
The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cat_title’ parameter from versions 1.3 to 2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever...
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.1
- Disclosed:
- Aug 1, 2014
BSK PDF Manager [bsk-pdf-manager] < 1.5
unknown
[en] Multiple SQL injection vulnerabilities in inc/bsk-pdf-dashboard.php in the BSK PDF Manager plugin 1.3.2 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) categoryid or (2) pdfid parameter to wp-admin/admin.php.
- Affected:
- up to 1.5
- Fixed in:
- 1.5
- Disclosed:
- Jul 14, 2014
CVE-2014-4944 on NVD →
BSK PDF Manager [bsk-pdf-manager] < 2.9.1
unknown
The plugin did not sanitise the view and cat_title POST parameter when creating or editing a category (/wp-admin/admin.php?page=bsk-pdf-manager), allowing authenticated users with a role as low as editor to set an XSS payload which will be triggered in the Categories list (wp-admin/admin.php?page=bsk-pdf-manager), Bulk...
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database