plugin

Legoeso Pdf Manager Vulnerabilities

1 known security issue reported for the Legoeso Pdf Manager WordPress plugin. Most recent disclosed Feb 19, 2025.

1 medium

Running Legoeso Pdf Manager on your site? Check whether your installed version is affected.

Scan your site free

Legoeso PDF Manager <= 1.2.2 - Authenticated (Author+) SQL Injection via checkedVals Parameter

medium

The Legoeso PDF Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘checkedVals’ parameter in all versions up to, and including, 1.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authent...

CVSS:
6.5
Affected:
up to 1.2.2
Fix:
No patched version reported
Disclosed:
Feb 19, 2025

CVE-2025-0866 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database