WordPress security by component
Videos sync PDF
Plugin description
Videos sync PDF is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published May 10, 2026; the highest CVE/CNA score is 7.5.
Plugin slug:
videos-sync-pdfLatest vulnerability
CVE-2022-50949: Videos sync PDF: Cross-site scripting
Videos sync PDF is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is 1.7.4.
| Safe version |
|
||
|---|---|---|---|
| May 10, 2026 |
CVE-2022-50949
Videos sync PDF: Cross-site scripting
Videos sync PDF is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is 1.7.4.
|
See mitigation notes |
CVE5.1
NVDPending
|
| Apr 25, 2022 |
CVE-2022-1392
Videos sync PDF: Filesystem traversal
Videos sync PDF is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE7.5
NVD7.5
|