Stored Cross-Site Scripting Vulnerability in E2Pdf Export PDF Tool for WordPress
CVE-2026-7650

6.4MEDIUM

What is CVE-2026-7650?

The E2Pdf – Export PDF Tool for WordPress has a vulnerability that allows authenticated users with Contributor-level access and above to exploit stored cross-site scripting. This issue arises from insufficient input sanitization and output escaping on the 'id' attribute of the 'e2pdf-download' shortcode, enabling the injection of arbitrary web scripts. Once these scripts are injected into pages, they will execute whenever a user accesses the compromised page, posing significant risks to users.

Affected Version(s)

E2Pdf – Export Pdf Tool for WordPress 0 <= 1.32.17

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Djaidja Moundjid
.