Impact
Improper Neutralization of Input During Web Page Generation allows attackers to store arbitrary JavaScript within PDFs generated by the WP Advanced PDF plugin. When any site visitor opens a affected PDF, the embedded script runs in the context of the visitor’s browser, potentially capturing cookies, hijacking sessions, or executing other client‑side attacks. This flaw is a classic input validation weakness classified as CWE‑79.
Affected Systems
The WP Advanced PDF plugin from cedcommerce, with any release version up to and including 1.1.7, is vulnerable. Any WordPress site that has installed the plugin at a version less than or equal to 1.1.7 is affected.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score is well below 1 %, suggesting a very low probability of active exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need a way to submit content through the plugin’s interface, which is normally restricted to administrators or content editors; this requirement is inferred from the plugin’s functionality, not explicitly stated in the CVE description.
OpenCVE Enrichment
EUVD