Impact
The Save as PDF Plugin by PDFCrowd for WordPress contains an arbitrary function invocation flaw that allows any authenticated Contributor or higher to supply a PHP callable via the pdf_created_callback shortcode attribute. During rendering the attribute is embedded into an AES‑encrypted blob without sanitisation or a whitelist. When a visitor posts this blob to the public wp_ajax_nopriv_save_as_pdf_pdfcrowd endpoint, the plugin decrypts it and calls the supplied function with no capability or is_callable check, enabling remote code execution and disclosure of stored API credentials. This is a CWE‑94 code injection vulnerability.
Affected Systems
WordPress sites that have the Save as PDF Plugin by PDFCrowd installed and enabled, specifically any release up to and including version 4.6.1, are affected. An attacker with Contributor or higher privileges on such a site can edit the shortcode attributes used by the plugin, triggering the exploit.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and while the EPSS score is not available, the lack of authorization checks and the ability to replay malicious blobs to an unauthenticated endpoint make exploitation likely in environments where the plugin is exposed. The vulnerability is not listed in CISA’s KEV catalog, but the possibility of arbitrary code execution or credential disclosure creates a significant risk to confidentiality, integrity and availability for affected sites, especially if an insider or compromised contributor account exists.
OpenCVE Enrichment