Executive brief
The PrintFriendly plugin for WordPress, which allows website visitors to easily print or save pages as PDFs, contains a security flaw. An attacker with administrative access can inject malicious scripts into the website's settings. These scripts will then run in the browsers of other users who visit the affected pages, potentially leading to unauthorized actions or data theft.
Technical details
The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'content_position_css' parameter. This vulnerability allows authenticated attackers with administrator-level permissions to inject arbitrary web scripts into the database. These scripts are then executed in the context of a user's browser whenever they access the modified pages. The attack requires network access and high privileges, but the impact is elevated because the script can execute in the context of other users (Scope: Changed). The issue affects all versions up to and including 5.5.10.
Affected products
- PrintFriendly Print, PDF & Email by PrintFriendly up to, and including, 5.5.10
Timeline
- 2026-07-11: disclosed
- 2026-07-11: advisory
References
- https://plugins.trac.wordpress.org/browser/printfriendly/tags/5.5.10/pf.php
- https://plugins.trac.wordpress.org/browser/printfriendly/tags/5.5.10/pf.php
- https://plugins.trac.wordpress.org/browser/printfriendly/tags/5.5.10/pf.php
- https://plugins.trac.wordpress.org/browser/printfriendly/tags/5.5.8/pf.php
- https://plugins.trac.wordpress.org/browser/printfriendly/tags/5.5.8/pf.php
- https://plugins.trac.wordpress.org/browser/printfriendly/tags/5.5.8/pf.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3590593%40printfriendly&new=3590593%40printfriendly