Description
Improper Control of Generation of Code ('Code Injection') vulnerability in termel PDF 2 Post pdf2post allows Remote Code Inclusion.This issue affects PDF 2 Post: from n/a through <= 2.4.0.
Published: 2025-04-17
Score: 9.9 Critical
EPSS: 16.0% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The PDF 2 Post plugin suffers from Improper Control of Generation of Code, allowing user‑supplied data to be incorporated into executable PHP. An attacker who can feed crafted content to the PDF generation endpoints can force the code to be executed, giving them full control of the WordPress site, enabling data exfiltration, or installation of additional malware.

Affected Systems

The vulnerability exists in all releases of the termel PDF 2 Post plugin up to and including version 2.4.0. WordPress sites running any of these versions are affected; newer releases beyond 2.4.0 are not known to be impacted.

Risk and Exploitability

The CVSS score of 9.9 indicates a very high severity impact, and the EPSS score of 16% suggests a relatively high likelihood that exploit attempts may be observed in the wild. The flaw is not listed in the CISA KEV catalogue. Attackers would likely target the plugin through crafted HTTP requests that trigger the creation of PDFs, exploiting the lack of input validation or proper access controls on those endpoints.

Generated by OpenCVE AI on August 3, 2026 at 08:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the PDF 2 Post plugin to the latest available version that fixes the RCE issue.
  • If an upgrade is not immediately possible, deactivate or uninstall the PDF 2 Post plugin to eliminate the vulnerable code path.
  • Deploy a web‑application firewall rule that blocks requests containing PHP code injection patterns directed at the PDF generation endpoints.

Generated by OpenCVE AI on August 3, 2026 at 08:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11691 Improper Control of Generation of Code ('Code Injection') vulnerability in termel PDF 2 Post allows Remote Code Inclusion. This issue affects PDF 2 Post: from n/a through 2.4.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Generation of Code ('Code Injection') vulnerability in termel PDF 2 Post allows Remote Code Inclusion. This issue affects PDF 2 Post: from n/a through 2.4.0. Improper Control of Generation of Code ('Code Injection') vulnerability in termel PDF 2 Post pdf2post allows Remote Code Inclusion.This issue affects PDF 2 Post: from n/a through <= 2.4.0.
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Thu, 17 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Generation of Code ('Code Injection') vulnerability in termel PDF 2 Post allows Remote Code Inclusion. This issue affects PDF 2 Post: from n/a through 2.4.0.
Title WordPress PDF 2 Post Plugin <= 2.4.0 - Remote Code Execution (RCE) vulnerability
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:24.837Z

Reserved: 2025-04-09T11:20:15.875Z

Link: CVE-2025-32583

cve-icon Vulnrichment

Updated: 2025-04-17T17:41:14.173Z

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:44.967

Modified: 2026-06-17T09:12:15.160

Link: CVE-2025-32583

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T08:30:17Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')