E2Pdf – Export Pdf Tool for WordPress <= 1.32.40 - Unauthenticated Local File Inclusion
high
The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.32.40. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be us...
- CVSS:
- 8.1
- Affected:
- up to 1.32.40
- Fixed in:
- 1.32.43
- Disclosed:
- Aug 5, 2026
CVE-2026-66710 on NVD →
E2Pdf <= 1.32.26 - Missing Authorization to Authenticated (Custom+) Arbitrary Option Update / Privilege Escalation via 'screen_action' Parameter
high
The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.32.26. This is due to the screen_action() function lacking a dedicated capability check and nonce verification — when invoked via the ?action=screen routing path the controller's ind...
- CVSS:
- 8.8
- Affected:
- up to 1.32.26
- Fixed in:
- 1.32.31
- Disclosed:
- Jun 17, 2026
CVE-2026-12407 on NVD →
E2Pdf – Export Pdf Tool for WordPress <= 1.32.14 - Reflected Cross-Site Scripting
medium
The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.32.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 1.32.14
- Fixed in:
- 1.32.15
- Disclosed:
- May 18, 2026
CVE-2026-42681 on NVD →
E2Pdf – Export Pdf Tool for WordPress <= 1.32.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute
medium
The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the `e2pdf-download` shortcode in all versions up to, and including, 1.32.17. This is due to insufficient input sanitization and output escaping on the shortcode attribute. This makes it...
- CVSS:
- 6.4
- Affected:
- up to 1.32.17
- Fixed in:
- 1.32.18
- Disclosed:
- May 7, 2026
CVE-2026-7650 on NVD →
e2pdf <= 1.28.15 - Missing Authorization
medium
The e2pdf plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.28.15. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.28.15
- Fixed in:
- 1.32.00
- Disclosed:
- Mar 4, 2026
CVE-2026-32442 on NVD →
e2pdf <= 1.28.09 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The e2pdf plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.28.09 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wil...
- CVSS:
- 6.4
- Affected:
- up to 1.28.09
- Fixed in:
- 1.28.10
- Disclosed:
- Oct 16, 2025
CVE-2025-62068 on NVD →
E2Pdf – Export Pdf Tool for WordPress [e2pdf] < 1.23.00
unknown
[en] Missing Authorization vulnerability in E2Pdf.Com allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects e2pdf: from n/a through 1.20.27.
- Affected:
- up to 1.23.00
- Fixed in:
- 1.23.00
- Disclosed:
- Nov 1, 2024
CVE-2024-37415 on NVD →
E2Pdf – Export Pdf Tool for WordPress [e2pdf] < 1.25.11
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E2Pdf.Com allows Stored XSS.This issue affects e2pdf: from n/a through 1.25.05.
- Affected:
- up to 1.25.11
- Fixed in:
- 1.25.11
- Disclosed:
- Aug 18, 2024
CVE-2024-43318 on NVD →
e2pdf <= 1.25.05 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The e2pdf plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.25.05 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wil...
- CVSS:
- 6.4
- Affected:
- up to 1.25.05
- Fixed in:
- 1.25.11
- Disclosed:
- Aug 16, 2024
CVE-2024-43318 on NVD →
E2Pdf – Export To Pdf Tool for WordPress <= 1.20.27 - Missing Authorization
medium
The E2Pdf – Export To Pdf Tool for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.20.27. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized act...
- CVSS:
- 4.3
- Affected:
- up to 1.20.27
- Fixed in:
- 1.23.00
- Disclosed:
- Jun 28, 2024
CVE-2024-37415 on NVD →
E2Pdf – Export Pdf Tool for WordPress [e2pdf] < 1.25.01
unknown
[en] A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
- Affected:
- up to 1.25.01
- Fixed in:
- 1.25.01
- Disclosed:
- May 14, 2024
CVE-2024-4367 on NVD →
E2Pdf – Export Pdf Tool for WordPress [e2pdf] < 1.23.00
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in E2Pdf.This issue affects e2pdf: from n/a through 1.20.27.
- Affected:
- up to 1.23.00
- Fixed in:
- 1.23.00
- Disclosed:
- Apr 15, 2024
CVE-2024-31373 on NVD →
e2pdf <= 1.20.27 - Cross-Site Request Forgery
medium
The e2pdf plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.20.27. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a s...
- CVSS:
- 4.3
- Affected:
- up to 1.20.27
- Fixed in:
- 1.23.00
- Disclosed:
- Apr 10, 2024
CVE-2024-31373 on NVD →
E2Pdf – Export Pdf Tool for WordPress [e2pdf] < 1.20.24
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in E2Pdf.Com E2Pdf – Export To Pdf Tool for WordPress.This issue affects E2Pdf – Export To Pdf Tool for WordPress: from n/a through 1.20.23.
- Affected:
- up to 1.20.24
- Fixed in:
- 1.20.24
- Disclosed:
- Dec 28, 2023
CVE-2023-50849 on NVD →
E2Pdf <= 1.20.23 - Authenticated(Administrator+) SQL Injection
medium
The E2Pdf – Export To Pdf Tool for WordPress plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to 1.20.24 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authen...
- CVSS:
- 6.6
- Affected:
- up to 1.20.24
- Fixed in:
- 1.20.24
- Disclosed:
- Dec 21, 2023
CVE-2023-50849 on NVD →
E2Pdf – Export Pdf Tool for WordPress [e2pdf] < 1.20.19
unknown
[en] Deserialization of Untrusted Data vulnerability in E2Pdf.Com E2Pdf – Export To Pdf Tool for WordPress.This issue affects E2Pdf – Export To Pdf Tool for WordPress: from n/a through 1.20.18.
- Affected:
- up to 1.20.19
- Fixed in:
- 1.20.19
- Disclosed:
- Dec 18, 2023
CVE-2023-46154 on NVD →
E2Pdf – Export Pdf Tool for WordPress [e2pdf] < 1.20.26
unknown
[en] The E2Pdf plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'import_action' function in versions up to, and including, 1.20.25. This makes it possible for authenticated attackers with a role that the administrator previously granted access to the plugin, t...
- Affected:
- up to 1.20.26
- Fixed in:
- 1.20.26
- Disclosed:
- Dec 15, 2023
CVE-2023-6826 on NVD →
E2Pdf <= 1.20.25 - Authenticated (Administrator+) Arbitrary File Upload
high
The E2Pdf plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'import_action' function in versions up to, and including, 1.20.25. This makes it possible for authenticated attackers with a role that the administrator previously granted access to the plugin, to upl...
- CVSS:
- 7.2
- Affected:
- up to 1.20.25
- Fixed in:
- 1.20.26
- Disclosed:
- Dec 13, 2023
CVE-2023-6826 on NVD →
E2Pdf – Export Pdf Tool for WordPress [e2pdf] < 1.20.20
unknown
[en] The E2Pdf WordPress plugin before 1.20.20 does not sanitize and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- Affected:
- up to 1.20.20
- Fixed in:
- 1.20.20
- Disclosed:
- Oct 31, 2023
CVE-2023-5229 on NVD →
E2Pdf <= 1.20.18 - Authenticated (Administrator+) PHP Object Injection
high
The E2Pdf plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.20.18 via deserialization of untrusted input within the import_action and ajax_upload functions. This makes it possible for authenticated attackers, with administrative-level access and above, to inject a PHP Ob...
- CVSS:
- 7.2
- Affected:
- up to 1.20.18
- Fixed in:
- 1.20.19
- Disclosed:
- Oct 17, 2023
CVE-2023-46154 on NVD →
e2pdf < 1.20.20 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The E2Pdf – Export To Pdf Tool for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to 1.20.20 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions...
- CVSS:
- 4.4
- Affected:
- up to 1.20.20
- Fixed in:
- 1.20.20
- Disclosed:
- Oct 9, 2023
CVE-2023-5229 on NVD →
E2Pdf – Export Pdf Tool for WordPress [e2pdf] < 1.16.45
unknown
[en] The E2Pdf WordPress plugin before 1.16.45 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- Affected:
- up to 1.16.45
- Fixed in:
- 1.16.45
- Disclosed:
- Mar 7, 2022
CVE-2022-0535 on NVD →
E2Pdf <= 1.16.44 - Stored Cross-Site Scripting
medium
The E2Pdf WordPress plugin before 1.16.45 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- CVSS:
- 4.8
- Affected:
- up to 1.16.44
- Fixed in:
- 1.16.45
- Disclosed:
- Feb 9, 2022
CVE-2022-0535 on NVD →
E2Pdf – Export Pdf Tool for WordPress [e2pdf] < 1.28.10
unknown
- Affected:
- up to 1.28.10
- Fixed in:
- 1.28.10
CVE-2025-62068 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database