Impact
The CVE describes a Cross‑Site Request Forgery vulnerability in the PDF Creator Lite plugin that allows an attacker to inject a malicious payload which becomes stored within the site. The attacker can then lure an authenticated user to execute the payload from the stored content, resulting in a stored cross‑site scripting attack. This flaw is classified as CWE-352 and can compromise the confidentiality, integrity, and availability of the website by enabling session hijacking, data theft, or defacement.
Affected Systems
The vulnerability affects the WordPress PDF Creator Lite plugin by Alex Furr, versions from the earliest release through 1.2. Any WordPress installation that has this plugin installed in a vulnerable version is at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity, while the EPSS score of < 1% suggests a low probability of exploitation at present. The flaw is not listed in CISA’s KEV catalog. The likely attack vector requires a victim who is authenticated to the site to visit a crafted URL that triggers the CSRF request, leading to the execution of the stored malicious payload.
OpenCVE Enrichment