BSK PDF Manager <= 3.7.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via SVG File Upload
BSK PDF Manager
Minimum safe version
3.7.2
Update to 3.7.2 or later to address 11 fixable vulnerabilities
Latest available3.8 ✓⚠ 1 vulnerability has no fix
N/A
2025-12-11< 3.7.2
Medium 5.3 Unfixed
2026-04-08≤ 3.7.2
CVE-2026-39686
Medium 6.5
2024-07-20< 3.6.1
CVE-2024-38767
High 8.8
2024-06-27< 3.6.1
WordPress BSK PDF Manager Plugin <= 3.6 is vulnerable to Cross Site Scripting (XSS)
Medium 5.4
2023-10-26< 3.4.2
WordPress BSK PDF Manager Plugin <= 3.4.1 is vulnerable to Cross Site Scripting (XSS)
N/A
2023-11-01< 3.1.2
WordPress BSK PDF Manager Plugin <= 3.1.1 is vulnerable to SQL Injection
N/A
2023-08-01< 1.4
WordPress BSK PDF Manager Plugin <= 1.3 is vulnerable to Cross Site Scripting (XSS)
N/A
2014-08-01< 2.9.1
BSK PDF Manager 1.3 - 2.9 - Authenticated Stored Cross-Site Scripting
N/A
< 2.9.1
BSK PDF Manager < 2.9.1 - Authenticated Stored Cross-Site Scripting (XSS)
N/A
2014-08-01< 1.4
WordPress BSK PDF Manager Plugin <= 1.3 - Cross Site Scripting
N/A
2014-08-01< 1.5
BSK PDF Manager <= 1.4 - Authenticated SQL Injection
High 7.2
2021-11-29< 3.1.2
CVE-2021-24860