Executive brief
The Save as PDF Plugin by PDFCrowd for WordPress allows attackers to execute arbitrary PHP functions on the web server. An authenticated contributor can craft a malicious PDF button shortcode that, when clicked by any visitor, executes arbitrary server-side functions—potentially exposing the site's API credentials or enabling further compromise.
Technical details
The vulnerability exists in the shortcode rendering and AJAX callback handling: the `eval_shortcode()` function accepts unsanitized shortcode attributes (including `pdf_created_callback`), encrypts them into a blob, and embeds this in the button HTML. When an unauthenticated user POSTs the blob to the `wp_ajax_nopriv_save_as_pdf_pdfcrowd` endpoint, `save_as_pdf_pdfcrowd()` decrypts and invokes the callback as a PHP callable without validation, allowing Contributor-level attackers to invoke arbitrary functions with plugin option data as the sole argument.
Affected products
- PDFCrowd Save as PDF Plugin up to and including 4.6.1
Timeline
- 2026-09-19: disclosed