plugin

Pdw File Browser Vulnerabilities

9 known security issues reported for the Pdw File Browser WordPress plugin. Most recent disclosed Jul 27, 2023.

1 high 1 medium

Running Pdw File Browser on your site? Check whether your installed version is affected.

Scan your site free

PDW Media File Browser [pdw-file-browser] < 1.1

unknown

Update the plugin. MustLive discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Pdw File Browser Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit yo...

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Jul 27, 2023

PDW Media File Browser [pdw-file-browser] < 1.1

unknown

Update plugin. Sammy FORGIT discovered and reported this Arbitrary File Upload vulnerability in WordPress Pdw File Browser Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website. This vulnerability...

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
May 15, 2023

PDF File Browser <= 1.3 - Remote Code Execution

high

The PDF File Browser plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.3 via the qqfile parameter. This allows authenticated attackers to execute code on the server.

CVSS:
8.8
Affected:
up to 1.3
Fix:
No patched version reported
Disclosed:
Oct 24, 2020

PDW Media File Browser [pdw-file-browser] <= 1.3 (unfixed)

unknown

The PDF File Browser plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.3 via the qqfile parameter. This allows authenticated attackers to execute code on the server.

Affected:
up to 1.3
Fix:
No patched version reported
Disclosed:
Oct 24, 2020

PDW Media File Browser [pdw-file-browser] < 1.1 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Jul 27, 2016

PDW Media File Browser [pdw-file-browser] <= 0.9.4.1 (closed)

unknown

This plugin is prone to an upload.php arbitrary file upload vulnerability. Update plugin.

Affected:
up to 0.9.4.1
Fixed in:
0.9.4.1
Disclosed:
May 15, 2015

PDW Media File Browser [pdw-file-browser] < 100 (unfixed + closed)

unknown

[en] Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.

Affected:
up to 100
Fix:
No patched version reported
Disclosed:
Jul 19, 2013

CVE-2012-3414 on NVD →

SWFUpload <= 2.2.0.1 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.

CVSS:
6.1
Affected:
up to *
Fix:
No patched version reported
Disclosed:
Nov 9, 2012

CVE-2012-3414 on NVD →

PDW Media File Browser [pdw-file-browser] <= 1.3 (unfixed + closed)

unknown

The pdw-file-browser WordPress plugin was affected by an upload.php Arbitrary File Upload security vulnerability.

Affected:
up to 1.3
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database