Impact
The PDF 2 Post plugin suffers from Improper Control of Generation of Code, allowing user‑supplied data to be incorporated into executable PHP. An attacker who can feed crafted content to the PDF generation endpoints can force the code to be executed, giving them full control of the WordPress site, enabling data exfiltration, or installation of additional malware.
Affected Systems
The vulnerability exists in all releases of the termel PDF 2 Post plugin up to and including version 2.4.0. WordPress sites running any of these versions are affected; newer releases beyond 2.4.0 are not known to be impacted.
Risk and Exploitability
The CVSS score of 9.9 indicates a very high severity impact, and the EPSS score of 16% suggests a relatively high likelihood that exploit attempts may be observed in the wild. The flaw is not listed in the CISA KEV catalogue. Attackers would likely target the plugin through crafted HTTP requests that trigger the creation of PDFs, exploiting the lack of input validation or proper access controls on those endpoints.
OpenCVE Enrichment
EUVD