CVE Database /
CVE-2024-3585
CVE · Medium
CVE-2024-3585 — Send PDF for Contact Form 7 [send-pdf-for-contact-form-7] < 1.0.2.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-3585
|
Send PDF for Contact Form 7 [send-pdf-for-contact-form-7] < 1.0.2.4 |
Missing Authorization |
Medium
5.3
|
< 1.0.2.4
|
1.0.2.4 |
2024-04-23 |
—
|
CVE-2024-3585
The Send PDF for Contact Form 7 plugin contains a capability check vulnerability affecting versions 1.0.2.3 and earlier, allowing unauthenticated users to access and download contact form submission data along with associated PDF files. The flaw exists in the plugin's hooks function where proper permission validation is absent, creating an exposure of sensitive form entry information to unauthorized parties. This vulnerability was patched in version 1.0.2.4.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings