Junglewise Threat Intelligence

CVE-2026-32473: PDF Smart Viewer for Elementor SSRF vulnerability

CVE-2026-32473 · Severity: high · CVSS 7.2 · Published 2026-08-18

Executive brief

PDF Smart Viewer for Elementor is a WordPress plugin that enables website visitors to view PDF files embedded on pages. An unauthenticated attacker can exploit a server-side request forgery flaw to make the vulnerable website server connect to internal systems or external targets, potentially exfiltrating sensitive data from behind firewalls or launching further attacks on internal infrastructure.

Technical details

A server-side request forgery (SSRF) vulnerability exists in PDF Smart Viewer for Elementor versions 1.0.4 and below, allowing unauthenticated attackers to craft malicious requests that force the server to make HTTP/HTTPS connections to arbitrary destinations. The vulnerability requires no authentication and is network-reachable, making it easily exploitable via simple HTTP requests. An attacker can leverage this to access internal resources (databases, metadata services, private APIs), exfiltrate sensitive data, or pivot attacks against internal systems. No official patch has been released as of the advisory date; Patchstack has provided a temporary mitigation rule to block exploitation attempts.

Affected products

  • PDF Smart Viewer for Elementor PDF Smart Viewer for Elementor <=1.0.4

Timeline

  • 2026-08-18: disclosed
  • 2026-01-22: other: Reported by Nabil Irawan

References