Access violation vulnerability in PDF Builder for WPForms 1.2.116

A plugin called “PDF Builder for WPForms” used in WordPress has a security issue where it reveals sensitive information about the website. This vulnerability exists in all versions up to 1.2.116. The plugin allows access to a file called “composer-setup.php” which shows error messages. This can be exploited by hackers to find the full path of the website, but it does not cause harm on its own. Another vulnerability would be needed for the website to be affected.

Detected in:

PDF Builder for WPForms fixed vulnerable versions: >= * <= 1.2.116

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.