Access Control Issue in PDF for WPForms by WordPress
CVE-2025-49289

5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 June 2025

What is CVE-2025-49289?

A missing authorization issue has been identified in the PDF for WPForms plugin, which permits attackers to exploit incorrectly configured access control security levels. This vulnerability can potentially allow unauthorized access, thereby compromising sensitive user data. It is crucial for users of PDF for WPForms versions up to 5.5.0 to review their security configurations and apply appropriate mitigations.

Affected Version(s)

PDF for WPForms <= 5.5.0

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Tran Tuan Dung (domiee13) (Patchstack Alliance)
.