Description
The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute. The `eval_shortcode()` function copies any non-`button_`/non-`email_` shortcode attribute verbatim into a custom options array without sanitization, allowlist enforcement, or capability checks, and `create_button()` AES-encrypts that array — including the attacker-supplied callback value — and embeds the resulting blob in the rendered button HTML; when the blob is later POSTed to the unauthenticated `wp_ajax_nopriv_save_as_pdf_pdfcrowd` endpoint, `save_as_pdf_pdfcrowd()` decrypts it and invokes `$options['pdf_created_callback']` as a PHP callable at line 1722 with no `is_callable()` guard, no allowlist, and no capability check. This makes it possible for authenticated attackers, with Contributor-level access and above, to invoke arbitrary PHP functions or static class methods with plugin option data as the sole argument, enabling disclosure of the site's stored PDFCrowd API key and username or further server-side abuse. Note that the encryption boundary does not mitigate this vector because the server itself encrypts the attacker-chosen callback during shortcode rendering, supplying any authenticated Contributor with a cryptographically valid blob that any unauthenticated visitor can subsequently replay to trigger invocation.
Published: 2026-09-19
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary PHP Function Invocation leading to remote code execution
Action: Apply Patch
AI Analysis

Impact

The Save as PDF Plugin by PDFCrowd for WordPress contains an arbitrary function invocation flaw that allows any authenticated Contributor or higher to supply a PHP callable via the pdf_created_callback shortcode attribute. During rendering the attribute is embedded into an AES‑encrypted blob without sanitisation or a whitelist. When a visitor posts this blob to the public wp_ajax_nopriv_save_as_pdf_pdfcrowd endpoint, the plugin decrypts it and calls the supplied function with no capability or is_callable check, enabling remote code execution and disclosure of stored API credentials. This is a CWE‑94 code injection vulnerability.

Affected Systems

WordPress sites that have the Save as PDF Plugin by PDFCrowd installed and enabled, specifically any release up to and including version 4.6.1, are affected. An attacker with Contributor or higher privileges on such a site can edit the shortcode attributes used by the plugin, triggering the exploit.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, and while the EPSS score is not available, the lack of authorization checks and the ability to replay malicious blobs to an unauthenticated endpoint make exploitation likely in environments where the plugin is exposed. The vulnerability is not listed in CISA’s KEV catalog, but the possibility of arbitrary code execution or credential disclosure creates a significant risk to confidentiality, integrity and availability for affected sites, especially if an insider or compromised contributor account exists.

Generated by OpenCVE AI on September 19, 2026 at 10:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Save as PDF Plugin to version 4.6.2 or later, which removes the vulnerability.
  • If an immediate upgrade is not possible, remove the plugin entirely or block the wp_ajax_nopriv_save_as_pdf_pdfcrowd endpoint via a security plugin or firewall.
  • If the plugin must remain in use, manually edit the plugin files to add a whitelist or is_callable guard before invoking the pdf_created_callback function.

Generated by OpenCVE AI on September 19, 2026 at 10:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Pdfcrowd
Pdfcrowd save As Pdf Plugin
Wordpress-extensions
Wordpress-extensions save As Pdf Plugin By Pdfcrowd
Vendors & Products Pdfcrowd
Pdfcrowd save As Pdf Plugin
Wordpress-extensions
Wordpress-extensions save As Pdf Plugin By Pdfcrowd

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute. The `eval_shortcode()` function copies any non-`button_`/non-`email_` shortcode attribute verbatim into a custom options array without sanitization, allowlist enforcement, or capability checks, and `create_button()` AES-encrypts that array — including the attacker-supplied callback value — and embeds the resulting blob in the rendered button HTML; when the blob is later POSTed to the unauthenticated `wp_ajax_nopriv_save_as_pdf_pdfcrowd` endpoint, `save_as_pdf_pdfcrowd()` decrypts it and invokes `$options['pdf_created_callback']` as a PHP callable at line 1722 with no `is_callable()` guard, no allowlist, and no capability check. This makes it possible for authenticated attackers, with Contributor-level access and above, to invoke arbitrary PHP functions or static class methods with plugin option data as the sole argument, enabling disclosure of the site's stored PDFCrowd API key and username or further server-side abuse. Note that the encryption boundary does not mitigate this vector because the server itself encrypts the attacker-chosen callback during shortcode rendering, supplying any authenticated Contributor with a cryptographically valid blob that any unauthenticated visitor can subsequently replay to trigger invocation.
Title Save as PDF Plugin by PDFCrowd <= 4.6.1 - Authenticated (Contributor+) Arbitrary Function Invocation / Code Injection via 'pdf_created_callback' Shortcode Attribute
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Pdfcrowd Save As Pdf Plugin
Wordpress-extensions Save As Pdf Plugin By Pdfcrowd
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:25.572Z

Reserved: 2026-09-16T19:48:03.924Z

Link: CVE-2026-92807

cve-icon Vulnrichment

Updated: 2026-09-19T13:56:00.665Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T03:17:17.723

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-92807

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:49:48Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')