Arbitrary Function Invocation in Save as PDF Plugin by PDFCrowd for WordPress
CVE-2026-92807
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 September 2026
What is CVE-2026-92807?
The Save as PDF Plugin by PDFCrowd for WordPress presents a security issue where an attacker can exploit arbitrary function invocation vulnerabilities. This occurs when using the pdf_created_callback shortcode attribute, allowing authenticated users with Contributor-level access or higher to execute arbitrary PHP functions or static class methods. The eval_shortcode() function lacks proper sanitization and capability checks while handling shortcode attributes, leading to unmitigated risks of exposing sensitive site information like the PDFCrowd API key. The vulnerability is exacerbated as attackers can craft a valid encrypted blob triggering save_as_pdf_pdfcrowd() to run arbitrary code without adequate defenses.
Affected Version(s)
Save as PDF Plugin by PDFCrowd 0 <= 4.6.1