Unauthenticated Local File Inclusion in e2pdf Plugin from WordPress
CVE-2026-66710
8.1HIGH
What is CVE-2026-66710?
The e2pdf plugin for WordPress is vulnerable to unauthenticated Local File Inclusion (LFI) in versions 1.32.40 and below. This vulnerability allows attackers to exploit the system, potentially gaining unauthorized access to sensitive files on the server. Proper patches and updates are crucial to mitigate risks associated with such vulnerabilities. Always ensure that you are using the latest version to maintain your site's security.
Affected Version(s)
e2pdf <= 1.32.40