plugin

Pdf For Wpforms Vulnerabilities

12 known security issues reported for the Pdf For Wpforms WordPress plugin. Most recent disclosed Feb 20, 2026.

1 high 5 medium

Running Pdf For Wpforms on your site? Check whether your installed version is affected.

Scan your site free

PDF for WPForms + Drag and Drop Template Builder [pdf-for-wpforms] <= 6.3.0 (unfixed)

unknown

[en] Missing Authorization vulnerability in add-ons.org PDF for WPForms pdf-for-wpforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDF for WPForms: from n/a through <= 6.3.0.

Affected:
up to 6.3.0
Fix:
No patched version reported
Disclosed:
Feb 20, 2026

CVE-2025-68534 on NVD →

PDF for WPForms <= 6.3.0 - Missing Authorization

medium

The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.3.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthoriz...

CVSS:
4.3
Affected:
up to 6.3.0
Fixed in:
6.3.1
Disclosed:
Feb 11, 2026

CVE-2025-68534 on NVD →

PDF for WPForms + Drag and Drop Template Builder [pdf-for-wpforms] <= 6.3.1 (unfixed)

unknown

[en] Deserialization of Untrusted Data vulnerability in add-ons.org PDF for WPForms pdf-for-wpforms allows Object Injection.This issue affects PDF for WPForms: from n/a through <= 6.3.1.

Affected:
up to 6.3.1
Fix:
No patched version reported
Disclosed:
Dec 18, 2025

CVE-2025-60082 on NVD →

PDF for WPForms <= 6.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The PDF for WPForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...

CVSS:
6.4
Affected:
up to 6.2.1
Fixed in:
6.3.0
Disclosed:
Sep 3, 2025

CVE-2025-58620 on NVD →

PDF for WPForms + Drag and Drop Template Builder [pdf-for-wpforms] < 6.3.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in add-ons.org PDF for WPForms allows Stored XSS. This issue affects PDF for WPForms: from n/a through 6.2.1.

Affected:
up to 6.3.0
Fixed in:
6.3.0
Disclosed:
Sep 3, 2025

CVE-2025-58620 on NVD →

PDF for WPForms <= 6.5.0 - Authenticated (Subscriber+) PHP Object Injection

high

The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known...

CVSS:
8.8
Affected:
up to 6.5.0
Fixed in:
6.5.1
Disclosed:
Aug 23, 2025

CVE-2025-60082 on NVD →

PDF for WPForms + Drag and Drop Template Builder [pdf-for-wpforms] < 5.6.1

unknown

[en] Missing Authorization vulnerability in add-ons.org PDF for WPForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF for WPForms: from n/a through 5.5.0.

Affected:
up to 5.6.1
Fixed in:
5.6.1
Disclosed:
Jun 6, 2025

CVE-2025-49289 on NVD →

PDF for WPForms <= 5.5.0 - Missing Authorization

medium

The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.5.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthoriz...

CVSS:
4.3
Affected:
up to 5.5.0
Fixed in:
5.6.1
Disclosed:
Jun 5, 2025

CVE-2025-49289 on NVD →

PDF for WPForms + Drag and Drop Template Builder [pdf-for-wpforms] < 5.3.1

unknown

[en] Missing Authorization vulnerability in add-ons.org PDF for WPForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF for WPForms: from n/a through 5.3.0.

Affected:
up to 5.3.1
Fixed in:
5.3.1
Disclosed:
Mar 27, 2025

CVE-2025-30767 on NVD →

PDF for WPForms <= 5.3.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution

medium

The The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.3.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it pos...

CVSS:
6.3
Affected:
up to 5.3.0
Fixed in:
5.3.1
Disclosed:
Mar 26, 2025

CVE-2025-30767 on NVD →

PDF for WPForms + Drag and Drop Template Builder [pdf-for-wpforms] < 4.8.0

unknown

[en] The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's yeepdf_dotab shortcode in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible f...

Affected:
up to 4.8.0
Fixed in:
4.8.0
Disclosed:
Jan 15, 2025

CVE-2024-12593 on NVD →

PDF for WPForms + Drag and Drop Template Builder <= 4.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via yeepdf_dotab Shortcode

medium

The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's yeepdf_dotab shortcode in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for au...

CVSS:
6.4
Affected:
up to 4.6.0
Fixed in:
4.8.0
Disclosed:
Jan 14, 2025

CVE-2024-12593 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database