Impact
This vulnerability in the WPMK PDF Generator plugin allows an attacker to perform a cross‑site request forgery which can result in client‑side code being stored as part of the plugin’s output. The stored code could potentially execute when the PDF content is rendered, giving the attacker a channel to inject malicious content into the site’s output.
Affected Systems
The WPMK PDF Generator plugin, versions from the earliest release up through 1.0.1, is affected. Any installation that has not been updated beyond 1.0.1 remains vulnerable.
Risk and Exploitability
The CVSS score of 7.1 marks this issue as high severity. The EPSS score of less than 1% indicates that the current likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would involve an attacker getting an authenticated administrator to submit a forged request that stores malicious code in the PDF generator’s output. Once the code is stored it can affect users who view the generated PDFs.
OpenCVE Enrichment
EUVD