Executive brief
A vulnerability exists in a WordPress plugin used for creating PDF templates from Elementor forms. This flaw allows users with low-level access, such as subscribers, to perform actions they should not be authorized to do. While the impact is considered low, it could allow unauthorized changes to plugin settings or templates, potentially affecting how documents are generated or managed on the site.
Technical details
The PDF for Elementor Forms + Drag And Drop Template Builder plugin for WordPress (versions up to 5.5.1) suffers from a missing authorization (CWE-862) vulnerability. The issue stems from incorrectly configured access control security levels within the plugin's functional logic. An attacker with Subscriber-level privileges can exploit this to execute actions that should be restricted to higher-privileged users. The vulnerability is reachable over the network without user interaction, though it requires valid low-level authentication. A fix is available in version 5.6.1.
Affected products
- ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder n/a through 5.5.1
Timeline
- 2025-05-14: other: Reported by researcher Nguyen Tran Tuan Dung
- 2026-05-20: advisory: Published by Patchstack and NVD
- 2026-05-20: patched: Version 5.6.1 released to address the issue