Vulnerabilities and security researches forformidablepro-2-pdf formidablepro-2-pdf
Direction: descendingJun 16, 2026
Formidable PRO2PDF # 571ea2704e844c3c96e05e7ae0f56701968f1f16
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 26, 2022
- Research Description
- Formidable PRO2PDF [formidablepro-2-pdf] < 3.10 WordPress Formidable PRO2PDF Plugin <= 3.09 is vulnerable to SQL Injection Update the WordPress Formidable PRO2PDF plugin to the latest available version (at least 3.10). Wordfence discovered and reported this SQL Injection vulnerability in WordPress Formidable PRO2PDF Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information and creating new administrator accounts. This vulnerability has been fixed in version 3.10.
- Affected versions
-
max 3.10.
- Status
-
vulnerable
Jun 10, 2024
Formidable PRO2PDF # CVE-2023-28663
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- The Formidable PRO2PDF plugin for WordPress is vulnerable to SQL Injection via several parameters in versions up to, and including, 3.09 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with administrative privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
- Affected versions
-
max 3.09.
- Status
-
vulnerable
Jun 07, 2024
Formidable PRO2PDF # 9edf05f0daa525bd6ee144e3e02d24e0339516f5
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 23, 2022
- Research Description
- Formidable PRO2PDF [formidablepro-2-pdf] < 3.10 Formidable PRO2PDF <= 3.09 - Authenticated (Admin+) SQL Injection The Formidable PRO2PDF plugin for WordPress is vulnerable to SQL Injection via several parameters in versions up to, and including, 3.09 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with administrative privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
- Affected versions
-
max 3.10.
- Status
-
vulnerable