Junglewise Threat Intelligence

CVE-2026-66710: e2pdf local file inclusion

CVE-2026-66710 · Severity: high · CVSS 8.1 · Published 2026-08-06

Executive brief

The e2pdf WordPress plugin enables users to generate PDF documents from website content. An unauthenticated attacker can exploit a local file inclusion vulnerability to read sensitive files from the server, such as configuration files containing database credentials or private keys. This could lead to unauthorized access to the site's database, customer data, or complete server compromise.

Technical details

The vulnerability is a local file inclusion (LFI) flaw in the e2pdf WordPress plugin versions up to 1.32.40. It allows unauthenticated attackers to read arbitrary files from the server filesystem via a path traversal attack or similar input validation bypass. The vulnerability requires no authentication and is accessible over the network, making it trivial to exploit at scale. Successful exploitation allows an attacker to access sensitive configuration files, source code, or other server files. The vulnerability has been patched in version 1.32.43 and later.

Affected products

  • E2Pdf.com e2pdf <= 1.32.40

Timeline

  • 2026-08-06: disclosed: CVE-2026-66710 published
  • 2026-08-05: patched: Patch released in version 1.32.43

References

Related threats