Description
Cross-Site Request Forgery (CSRF) vulnerability in kubiq PDF Thumbnail Generator pdf-thumbnail-generator allows Cross Site Request Forgery.This issue affects PDF Thumbnail Generator: from n/a through <= 1.4.
Published: 2025-12-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, it is inferred that the vulnerability is a classic CSRF flaw in the PDF Thumbnail Generator plugin for WordPress. An attacker can craft a malicious web page or link that, when visited by a logged‑in user, causes the plugin to perform a thumbnail generation request without the user’s explicit consent. This can lead to unauthorized resource processing or the creation of thumbnails from files that the user has not intended to share, potentially exposing sensitive information or consuming server resources.

Affected Systems

Based on the description, it is inferred that all installations of kubiq PDF Thumbnail Generator up to and including version 1.4 are vulnerable. The affected product is the WordPress plugin “PDF Thumbnail Generator” distributed by kubiq, which may appear on any WordPress site that has installed a version through 1.4. The vulnerability affects all WordPress users who are authenticated and can access the plugin’s thumbnail generation endpoint.

Risk and Exploitability

Based on the description, it is inferred that the attack vector is a victim visiting a crafted page that initiates an HTTP request to the plugin’s endpoint; the attacker does not need any direct network access to the target beyond the ability to embed malicious content. The CVSS score of 4.3 indicates moderate severity; the EPSS score of less than 1% indicates that, historically, exploit attempts are rare. The vulnerability is not listed in the CISA KEV catalog. The attacker benefits from the victim’s authenticated session, and the impact is limited to the actions that the compromised user is permitted to perform through the plugin’s interface.

Generated by OpenCVE AI on April 30, 2026 at 05:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the PDF Thumbnail Generator plugin to the latest version that includes the CSRF fix.
  • If an upgrade cannot be performed immediately, configure the plugin or WordPress to restrict the thumbnail generation endpoint to administrative or privileged users and ensure that CSRF nonces are enforced for all state‑changing requests.
  • Consider deactivating or uninstalling the plugin until the patch is applied to eliminate the attack surface.

Generated by OpenCVE AI on April 30, 2026 at 05:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 11 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 10 Dec 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Kubiq
Kubiq pdf Thumbnail Generator
Wordpress
Wordpress wordpress
Vendors & Products Kubiq
Kubiq pdf Thumbnail Generator
Wordpress
Wordpress wordpress

Tue, 09 Dec 2025 14:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in kubiq PDF Thumbnail Generator pdf-thumbnail-generator allows Cross Site Request Forgery.This issue affects PDF Thumbnail Generator: from n/a through <= 1.4.
Title WordPress PDF Thumbnail Generator plugin <= 1.4 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References

Subscriptions

Kubiq Pdf Thumbnail Generator
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:19.608Z

Reserved: 2025-12-08T16:00:53.489Z

Link: CVE-2025-67469

cve-icon Vulnrichment

Updated: 2025-12-11T19:02:29.108Z

cve-icon NVD

Status : Deferred

Published: 2025-12-09T16:18:23.123

Modified: 2026-04-27T18:16:39.420

Link: CVE-2025-67469

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T05:15:28Z

Weaknesses