Arbitrary Function Invocation in Save as PDF Plugin by PDFCrowd for WordPress
CVE-2026-92807

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 September 2026

What is CVE-2026-92807?

The Save as PDF Plugin by PDFCrowd for WordPress presents a security issue where an attacker can exploit arbitrary function invocation vulnerabilities. This occurs when using the pdf_created_callback shortcode attribute, allowing authenticated users with Contributor-level access or higher to execute arbitrary PHP functions or static class methods. The eval_shortcode() function lacks proper sanitization and capability checks while handling shortcode attributes, leading to unmitigated risks of exposing sensitive site information like the PDFCrowd API key. The vulnerability is exacerbated as attackers can craft a valid encrypted blob triggering save_as_pdf_pdfcrowd() to run arbitrary code without adequate defenses.

Affected Version(s)

Save as PDF Plugin by PDFCrowd 0 <= 4.6.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.