Junglewise Threat Intelligence

CVE-2026-42681: E2Pdf.Com e2pdf Reflected XSS

CVE-2026-42681 · Severity: high · CVSS 7.1 · Published 2026-06-01

Executive brief

E2Pdf is a WordPress plugin used to create and edit PDF documents directly from the website dashboard. A security flaw in this plugin allows attackers to trick a user into clicking a malicious link, which then executes unauthorized code in the user's browser. This can lead to the theft of login sessions, unauthorized website changes, or the redirection of visitors to malicious sites.

Technical details

The E2Pdf plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) due to insufficient neutralization of user-supplied input during web page generation. An unauthenticated remote attacker can exploit this by sending a specially crafted link to a site administrator or visitor. If the victim clicks the link, the malicious script is executed within the context of their browser session. This can result in the disclosure of sensitive information, such as session cookies, or the execution of arbitrary actions on behalf of the user. The vulnerability is fixed in version 1.32.15.

Affected products

  • E2Pdf.Com e2pdf up to 1.32.14

Timeline

  • 2026-04-18: disclosed: Reported by hhhai via Patchstack VDP
  • 2026-05-18: advisory: Patchstack published advisory details
  • 2026-06-01: advisory: CVE published to NVD dataset

References

Related threats