Stored Cross-Site Scripting Vulnerability in E2Pdf Export PDF Tool for WordPress
CVE-2026-7650
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 May 2026
What is CVE-2026-7650?
The E2Pdf β Export PDF Tool for WordPress has a vulnerability that allows authenticated users with Contributor-level access and above to exploit stored cross-site scripting. This issue arises from insufficient input sanitization and output escaping on the 'id' attribute of the 'e2pdf-download' shortcode, enabling the injection of arbitrary web scripts. Once these scripts are injected into pages, they will execute whenever a user accesses the compromised page, posing significant risks to users.
Affected Version(s)
E2Pdf β Export Pdf Tool for WordPress 0 <= 1.32.17