Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pdfcrowd Dev Team Save as PDF save-as-pdf-by-pdfcrowd allows Stored XSS.This issue affects Save as PDF: from n/a through <= 4.5.2.
Published: 2025-09-22
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability appears as an improper neutralization of input during web page generation, allowing a stored XSS attack. An attacker can inject malicious JavaScript that will be executed in the browsers of anyone viewing the compromised content. The effect can include defacement, cookie theft, or redirection, thereby compromising confidentiality, integrity, or availability of user sessions.

Affected Systems

Pdfcrowd Dev Team’s Save as PDF plugin for WordPress, versions 4.5.2 and earlier. No additional version constraints are listed.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1 % signals a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers could exploit it via the plugin’s data submission interface, requiring no elevated privileges on the site. Although the risk is moderate, the low EPSS suggests limited impact in the wild today. However, if an attacker gains write access through the plugin, they could supply malicious payloads that are rendered for all visitors.

Generated by OpenCVE AI on April 30, 2026 at 00:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Save as PDF to a version newer than 4.5.2.
  • If an upgrade is not possible, remove or disable the plugin to eliminate the stored XSS risk.
  • Configure a web application firewall or output sanitization to block scripts on plugin input.

Generated by OpenCVE AI on April 30, 2026 at 00:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-30493 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pdfcrowd Dev Team Save as PDF allows Stored XSS. This issue affects Save as PDF: from n/a through 4.5.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pdfcrowd Dev Team Save as PDF allows Stored XSS. This issue affects Save as PDF: from n/a through 4.5.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pdfcrowd Dev Team Save as PDF save-as-pdf-by-pdfcrowd allows Stored XSS.This issue affects Save as PDF: from n/a through <= 4.5.2.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 23 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Pdfcrowd
Pdfcrowd save As Pdf
Pdfcrowd save As Pdf Plugin
Wordpress
Wordpress wordpress
Vendors & Products Pdfcrowd
Pdfcrowd save As Pdf
Pdfcrowd save As Pdf Plugin
Wordpress
Wordpress wordpress

Mon, 22 Sep 2025 18:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pdfcrowd Dev Team Save as PDF allows Stored XSS. This issue affects Save as PDF: from n/a through 4.5.2.
Title WordPress Save as PDF Plugin <= 4.5.2 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Pdfcrowd Save As Pdf Save As Pdf Plugin
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:52.230Z

Reserved: 2025-09-17T18:00:39.585Z

Link: CVE-2025-59552

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2025-09-22T19:16:23.810

Modified: 2026-04-23T15:34:03.420

Link: CVE-2025-59552

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T00:30:23Z

Weaknesses