PT-2026-95747 · Pdfcrowd · Save As Pdf Plugin
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Save as PDF Plugin by PDFCrowd versions prior to 4.6.2
Description
The plugin is susceptible to Arbitrary Function Invocation. The
eval shortcode() function copies shortcode attributes into a custom options array without sanitization or capability checks. The create button() function then AES-encrypts this array, including the pdf created callback attribute, and embeds it in the button HTML. When this encrypted blob is sent to the unauthenticated wp ajax nopriv save as pdf pdfcrowd endpoint, the save as pdf pdfcrowd() function decrypts it and executes the value of pdf created callback as a PHP callable without validation. This allows authenticated attackers with Contributor-level access or higher to invoke arbitrary PHP functions or static class methods, potentially leading to the disclosure of the PDFCrowd API key and username or other server-side abuse.Recommendations
Update the plugin to a version newer than 4.6.1.
As a temporary mitigation, restrict the ability of users with Contributor-level access to create or edit shortcodes.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Save As Pdf Plugin