Input validation vulnerability in WordPress PDF Light Viewer Plugin 1.4.11

The WordPress PDF Light Viewer Plugin is a type of program used on WordPress websites. A vulnerability was discovered in versions of this plugin released before 1.4.12 that allowed people with an “”Author”” role on the website to run malicious commands on the server. This was done by exploiting a security hole known as an “”OS Command Injection””.

Detected in:

WordPress PDF Light Viewer Plugin fixed vulnerable versions: >= * <= 1.4.11

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.