plugin

E2Pdf Vulnerabilities

24 known security issues reported for the E2Pdf WordPress plugin. Most recent disclosed Aug 5, 2026.

4 high 10 medium

Running E2Pdf on your site? Check whether your installed version is affected.

Scan your site free

E2Pdf – Export Pdf Tool for WordPress <= 1.32.40 - Unauthenticated Local File Inclusion

high

The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.32.40. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be us...

CVSS:
8.1
Affected:
up to 1.32.40
Fixed in:
1.32.43
Disclosed:
Aug 5, 2026

CVE-2026-66710 on NVD →

E2Pdf <= 1.32.26 - Missing Authorization to Authenticated (Custom+) Arbitrary Option Update / Privilege Escalation via 'screen_action' Parameter

high

The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.32.26. This is due to the screen_action() function lacking a dedicated capability check and nonce verification — when invoked via the ?action=screen routing path the controller's ind...

CVSS:
8.8
Affected:
up to 1.32.26
Fixed in:
1.32.31
Disclosed:
Jun 17, 2026

CVE-2026-12407 on NVD →

E2Pdf – Export Pdf Tool for WordPress <= 1.32.14 - Reflected Cross-Site Scripting

medium

The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.32.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
up to 1.32.14
Fixed in:
1.32.15
Disclosed:
May 18, 2026

CVE-2026-42681 on NVD →

E2Pdf – Export Pdf Tool for WordPress <= 1.32.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute

medium

The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the `e2pdf-download` shortcode in all versions up to, and including, 1.32.17. This is due to insufficient input sanitization and output escaping on the shortcode attribute. This makes it...

CVSS:
6.4
Affected:
up to 1.32.17
Fixed in:
1.32.18
Disclosed:
May 7, 2026

CVE-2026-7650 on NVD →

e2pdf <= 1.28.15 - Missing Authorization

medium

The e2pdf plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.28.15. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 1.28.15
Fixed in:
1.32.00
Disclosed:
Mar 4, 2026

CVE-2026-32442 on NVD →

e2pdf <= 1.28.09 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The e2pdf plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.28.09 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wil...

CVSS:
6.4
Affected:
up to 1.28.09
Fixed in:
1.28.10
Disclosed:
Oct 16, 2025

CVE-2025-62068 on NVD →

E2Pdf &#8211; Export Pdf Tool for WordPress [e2pdf] < 1.23.00

unknown

[en] Missing Authorization vulnerability in E2Pdf.Com allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects e2pdf: from n/a through 1.20.27.

Affected:
up to 1.23.00
Fixed in:
1.23.00
Disclosed:
Nov 1, 2024

CVE-2024-37415 on NVD →

E2Pdf &#8211; Export Pdf Tool for WordPress [e2pdf] < 1.25.11

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E2Pdf.Com allows Stored XSS.This issue affects e2pdf: from n/a through 1.25.05.

Affected:
up to 1.25.11
Fixed in:
1.25.11
Disclosed:
Aug 18, 2024

CVE-2024-43318 on NVD →

e2pdf <= 1.25.05 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The e2pdf plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.25.05 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wil...

CVSS:
6.4
Affected:
up to 1.25.05
Fixed in:
1.25.11
Disclosed:
Aug 16, 2024

CVE-2024-43318 on NVD →

E2Pdf – Export To Pdf Tool for WordPress <= 1.20.27 - Missing Authorization

medium

The E2Pdf – Export To Pdf Tool for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.20.27. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized act...

CVSS:
4.3
Affected:
up to 1.20.27
Fixed in:
1.23.00
Disclosed:
Jun 28, 2024

CVE-2024-37415 on NVD →

E2Pdf &#8211; Export Pdf Tool for WordPress [e2pdf] < 1.25.01

unknown

[en] A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

Affected:
up to 1.25.01
Fixed in:
1.25.01
Disclosed:
May 14, 2024

CVE-2024-4367 on NVD →

E2Pdf &#8211; Export Pdf Tool for WordPress [e2pdf] < 1.23.00

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in E2Pdf.This issue affects e2pdf: from n/a through 1.20.27.

Affected:
up to 1.23.00
Fixed in:
1.23.00
Disclosed:
Apr 15, 2024

CVE-2024-31373 on NVD →

e2pdf <= 1.20.27 - Cross-Site Request Forgery

medium

The e2pdf plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.20.27. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a s...

CVSS:
4.3
Affected:
up to 1.20.27
Fixed in:
1.23.00
Disclosed:
Apr 10, 2024

CVE-2024-31373 on NVD →

E2Pdf &#8211; Export Pdf Tool for WordPress [e2pdf] < 1.20.24

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in E2Pdf.Com E2Pdf – Export To Pdf Tool for WordPress.This issue affects E2Pdf – Export To Pdf Tool for WordPress: from n/a through 1.20.23.

Affected:
up to 1.20.24
Fixed in:
1.20.24
Disclosed:
Dec 28, 2023

CVE-2023-50849 on NVD →

E2Pdf <= 1.20.23 - Authenticated(Administrator+) SQL Injection

medium

The E2Pdf – Export To Pdf Tool for WordPress plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to 1.20.24 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authen...

CVSS:
6.6
Affected:
up to 1.20.24
Fixed in:
1.20.24
Disclosed:
Dec 21, 2023

CVE-2023-50849 on NVD →

E2Pdf &#8211; Export Pdf Tool for WordPress [e2pdf] < 1.20.19

unknown

[en] Deserialization of Untrusted Data vulnerability in E2Pdf.Com E2Pdf – Export To Pdf Tool for WordPress.This issue affects E2Pdf – Export To Pdf Tool for WordPress: from n/a through 1.20.18.

Affected:
up to 1.20.19
Fixed in:
1.20.19
Disclosed:
Dec 18, 2023

CVE-2023-46154 on NVD →

E2Pdf &#8211; Export Pdf Tool for WordPress [e2pdf] < 1.20.26

unknown

[en] The E2Pdf plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'import_action' function in versions up to, and including, 1.20.25. This makes it possible for authenticated attackers with a role that the administrator previously granted access to the plugin, t...

Affected:
up to 1.20.26
Fixed in:
1.20.26
Disclosed:
Dec 15, 2023

CVE-2023-6826 on NVD →

E2Pdf <= 1.20.25 - Authenticated (Administrator+) Arbitrary File Upload

high

The E2Pdf plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'import_action' function in versions up to, and including, 1.20.25. This makes it possible for authenticated attackers with a role that the administrator previously granted access to the plugin, to upl...

CVSS:
7.2
Affected:
up to 1.20.25
Fixed in:
1.20.26
Disclosed:
Dec 13, 2023

CVE-2023-6826 on NVD →

E2Pdf &#8211; Export Pdf Tool for WordPress [e2pdf] < 1.20.20

unknown

[en] The E2Pdf WordPress plugin before 1.20.20 does not sanitize and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Affected:
up to 1.20.20
Fixed in:
1.20.20
Disclosed:
Oct 31, 2023

CVE-2023-5229 on NVD →

E2Pdf <= 1.20.18 - Authenticated (Administrator+) PHP Object Injection

high

The E2Pdf plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.20.18 via deserialization of untrusted input within the import_action and ajax_upload functions. This makes it possible for authenticated attackers, with administrative-level access and above, to inject a PHP Ob...

CVSS:
7.2
Affected:
up to 1.20.18
Fixed in:
1.20.19
Disclosed:
Oct 17, 2023

CVE-2023-46154 on NVD →

e2pdf < 1.20.20 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The E2Pdf – Export To Pdf Tool for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to 1.20.20 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions...

CVSS:
4.4
Affected:
up to 1.20.20
Fixed in:
1.20.20
Disclosed:
Oct 9, 2023

CVE-2023-5229 on NVD →

E2Pdf &#8211; Export Pdf Tool for WordPress [e2pdf] < 1.16.45

unknown

[en] The E2Pdf WordPress plugin before 1.16.45 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Affected:
up to 1.16.45
Fixed in:
1.16.45
Disclosed:
Mar 7, 2022

CVE-2022-0535 on NVD →

E2Pdf <= 1.16.44 - Stored Cross-Site Scripting

medium

The E2Pdf WordPress plugin before 1.16.45 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVSS:
4.8
Affected:
up to 1.16.44
Fixed in:
1.16.45
Disclosed:
Feb 9, 2022

CVE-2022-0535 on NVD →

E2Pdf &#8211; Export Pdf Tool for WordPress [e2pdf] < 1.28.10

unknown
Affected:
up to 1.28.10
Fixed in:
1.28.10

CVE-2025-62068 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database