PT-2026-95747 · Pdfcrowd · Save As Pdf Plugin

·

CVE-2026-92807

·

Published

2026-09-19

·

Updated

2026-09-25

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Save as PDF Plugin by PDFCrowd versions prior to 4.6.2
Description The plugin is susceptible to Arbitrary Function Invocation. The eval shortcode() function copies shortcode attributes into a custom options array without sanitization or capability checks. The create button() function then AES-encrypts this array, including the pdf created callback attribute, and embeds it in the button HTML. When this encrypted blob is sent to the unauthenticated wp ajax nopriv save as pdf pdfcrowd endpoint, the save as pdf pdfcrowd() function decrypts it and executes the value of pdf created callback as a PHP callable without validation. This allows authenticated attackers with Contributor-level access or higher to invoke arbitrary PHP functions or static class methods, potentially leading to the disclosure of the PDFCrowd API key and username or other server-side abuse.
Recommendations Update the plugin to a version newer than 4.6.1. As a temporary mitigation, restrict the ability of users with Contributor-level access to create or edit shortcodes.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92807

Affected Products

Save As Pdf Plugin