Junglewise Threat Intelligence

CVE-2026-92807: PDFCrowd Save as PDF Plugin arbitrary function invocation

CVE-2026-92807 · Severity: high · CVSS 8.8 · Published 2026-09-19

Executive brief

The Save as PDF Plugin by PDFCrowd for WordPress allows attackers to execute arbitrary PHP functions on the web server. An authenticated contributor can craft a malicious PDF button shortcode that, when clicked by any visitor, executes arbitrary server-side functions—potentially exposing the site's API credentials or enabling further compromise.

Technical details

The vulnerability exists in the shortcode rendering and AJAX callback handling: the `eval_shortcode()` function accepts unsanitized shortcode attributes (including `pdf_created_callback`), encrypts them into a blob, and embeds this in the button HTML. When an unauthenticated user POSTs the blob to the `wp_ajax_nopriv_save_as_pdf_pdfcrowd` endpoint, `save_as_pdf_pdfcrowd()` decrypts and invokes the callback as a PHP callable without validation, allowing Contributor-level attackers to invoke arbitrary functions with plugin option data as the sole argument.

Affected products

  • PDFCrowd Save as PDF Plugin up to and including 4.6.1

Timeline

  • 2026-09-19: disclosed

References