IMPORTANT UPDATE: Please DOWNLOAD and update the Formidable PRO2PDF to the Latest Version!

My Wordfence says 3.09 has a Security Vulnerability, where is 3.10?

Home Forums Pre-Sale My Wordfence says 3.09 has a Security Vulnerability, where is 3.10?

Tagged: 

Viewing 2 posts - 1 through 2 (of 2 total)
  • Author
    Posts
  • #48089 Reply
    linda2
    Participant

    Description

    The Formidable PRO2PDF plugin for WordPress is vulnerable to SQL Injection via several parameters in versions up to, and including, 3.09 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with administrative privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
    References

    plugins.trac.wordpress.org
    1 affected software package
    Formidable PRO2PDF
    Software Type Plugin
    Software Slug formidablepro-2-pdf (view on wordpress.org)
    Patched? Yes
    Remediation Update to version 3.10, or a newer patched version
    Affected Version

    <= 3.09

    Patched Version

    3.10

    #48622 Reply
    admin2
    Keymaster

    Hi,

    Please download and update the plugin manually until the update will not be available at WordPress.org:

    https://www.formidablepro2pdf.com/formidablepro-2-pdf.zip

    Let us know please if it will be any issues after the update.

    We remain at your service.

    • This reply was modified 1 year, 1 month ago by admin2.
Viewing 2 posts - 1 through 2 (of 2 total)
Reply To: Reply #48622 in My Wordfence says 3.09 has a Security Vulnerability, where is 3.10?
Your information: