Unauthenticated Local File Inclusion in e2pdf Plugin from WordPress
CVE-2026-66710

8.1HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-66710?

The e2pdf plugin for WordPress is vulnerable to unauthenticated Local File Inclusion (LFI) in versions 1.32.40 and below. This vulnerability allows attackers to exploit the system, potentially gaining unauthorized access to sensitive files on the server. Proper patches and updates are crucial to mitigate risks associated with such vulnerabilities. Always ensure that you are using the latest version to maintain your site's security.

Affected Version(s)

e2pdf <= 1.32.40

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Noman Riffat | Patchstack Bug Bounty Program
.