PDF for WPForms + Drag and Drop Template Builder [pdf-for-wpforms] <= 6.3.0 (unfixed)
unknown
[en] Missing Authorization vulnerability in add-ons.org PDF for WPForms pdf-for-wpforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDF for WPForms: from n/a through <= 6.3.0.
- Affected:
- up to 6.3.0
- Fix:
- No patched version reported
- Disclosed:
- Feb 20, 2026
CVE-2025-68534 on NVD →
PDF for WPForms <= 6.3.0 - Missing Authorization
medium
The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.3.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthoriz...
- CVSS:
- 4.3
- Affected:
- up to 6.3.0
- Fixed in:
- 6.3.1
- Disclosed:
- Feb 11, 2026
CVE-2025-68534 on NVD →
PDF for WPForms + Drag and Drop Template Builder [pdf-for-wpforms] <= 6.3.1 (unfixed)
unknown
[en] Deserialization of Untrusted Data vulnerability in add-ons.org PDF for WPForms pdf-for-wpforms allows Object Injection.This issue affects PDF for WPForms: from n/a through <= 6.3.1.
- Affected:
- up to 6.3.1
- Fix:
- No patched version reported
- Disclosed:
- Dec 18, 2025
CVE-2025-60082 on NVD →
PDF for WPForms <= 6.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The PDF for WPForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...
- CVSS:
- 6.4
- Affected:
- up to 6.2.1
- Fixed in:
- 6.3.0
- Disclosed:
- Sep 3, 2025
CVE-2025-58620 on NVD →
PDF for WPForms + Drag and Drop Template Builder [pdf-for-wpforms] < 6.3.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in add-ons.org PDF for WPForms allows Stored XSS. This issue affects PDF for WPForms: from n/a through 6.2.1.
- Affected:
- up to 6.3.0
- Fixed in:
- 6.3.0
- Disclosed:
- Sep 3, 2025
CVE-2025-58620 on NVD →
PDF for WPForms <= 6.5.0 - Authenticated (Subscriber+) PHP Object Injection
high
The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known...
- CVSS:
- 8.8
- Affected:
- up to 6.5.0
- Fixed in:
- 6.5.1
- Disclosed:
- Aug 23, 2025
CVE-2025-60082 on NVD →
PDF for WPForms + Drag and Drop Template Builder [pdf-for-wpforms] < 5.6.1
unknown
[en] Missing Authorization vulnerability in add-ons.org PDF for WPForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF for WPForms: from n/a through 5.5.0.
- Affected:
- up to 5.6.1
- Fixed in:
- 5.6.1
- Disclosed:
- Jun 6, 2025
CVE-2025-49289 on NVD →
PDF for WPForms <= 5.5.0 - Missing Authorization
medium
The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.5.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthoriz...
- CVSS:
- 4.3
- Affected:
- up to 5.5.0
- Fixed in:
- 5.6.1
- Disclosed:
- Jun 5, 2025
CVE-2025-49289 on NVD →
PDF for WPForms + Drag and Drop Template Builder [pdf-for-wpforms] < 5.3.1
unknown
[en] Missing Authorization vulnerability in add-ons.org PDF for WPForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF for WPForms: from n/a through 5.3.0.
- Affected:
- up to 5.3.1
- Fixed in:
- 5.3.1
- Disclosed:
- Mar 27, 2025
CVE-2025-30767 on NVD →
PDF for WPForms <= 5.3.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution
medium
The The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.3.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it pos...
- CVSS:
- 6.3
- Affected:
- up to 5.3.0
- Fixed in:
- 5.3.1
- Disclosed:
- Mar 26, 2025
CVE-2025-30767 on NVD →
PDF for WPForms + Drag and Drop Template Builder [pdf-for-wpforms] < 4.8.0
unknown
[en] The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's yeepdf_dotab shortcode in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible f...
- Affected:
- up to 4.8.0
- Fixed in:
- 4.8.0
- Disclosed:
- Jan 15, 2025
CVE-2024-12593 on NVD →
PDF for WPForms + Drag and Drop Template Builder <= 4.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via yeepdf_dotab Shortcode
medium
The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's yeepdf_dotab shortcode in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for au...
- CVSS:
- 6.4
- Affected:
- up to 4.6.0
- Fixed in:
- 4.8.0
- Disclosed:
- Jan 14, 2025
CVE-2024-12593 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database