DECIPHERU · INTELLIGENCECVE

ByJulian Calvo, Ed.D., M.S.Founder, DecipherU
HIGHCVESeptember 19, 2026

CVE-2026-92807, The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitra...

Source: nvd.nist.gov (CVE-2026-92807) · September 19, 2026
DecipherU Intelligence aggregates cybersecurity developments from government databases, official filings, and authoritative sources. The summary below is written by DecipherU and does not represent the views of the original source. For full details, follow the source link.

Summary

The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute. The `eval_shortcode()` function copies any non-`button_`/non-`email_` shortcode attribute verbatim into a custom options array without sanitization, allowlist enforcement, or capability checks, and `create_button()` AES-encrypts that array — including the attacker-supplied callback value — and embeds the resulting blob in the rendered button HTML; when the blob is later POSTed to the unauthenticated `wp_ajax_nopriv_save_as_pdf_pdfcrowd` endpoint, `save_as_pdf_pdfcrowd()` decrypts it and invokes `$options['pdf_created_callback']` as a PHP callable at line 1722 with no `is_callable()` guard, no allowlist, and no capability check. This makes it possible for authenticated attackers, with Contributor-level access and above, to invoke arbitrary PHP functions or static class methods with plugin option data as the sole argument, enabling disclosure of the site's stored PDFCrowd API key and username or further server-side abuse. Note that the encryption boundary does not mitigate this vector because the server itself encrypts the attacker-chosen callback during shortcode rendering, supplying any authenticated Contributor with a cryptographically valid blob that any unauthenticated visitor can subsequently replay to trigger invocation.

Relevant Roles

incident-respondersoc-analystsecurity-engineer

For the full cve details, visit the original source.

Read Original Source: nvd.nist.gov
Source: nvd.nist.gov, September 19, 2026. This summary is DecipherU's original writing. For complete details, follow the source link above. This page is for informational purposes only and does not constitute security advice.

Sources

  1. NIST National Vulnerability Database (NVD) · Authoritative CVE records and CVSS scoring.
  2. CISA Advisories · Public-domain US Cybersecurity and Infrastructure Security Agency alerts.
  3. DecipherU Live Feeds · DecipherU aggregates and curates these cybersecurity intelligence items.
Last verified: September 19, 2026?Report an inaccuracy