What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in E2Pdf.Com E2Pdf – Export To Pdf Tool for WordPress.This issue affects E2Pdf – Export To Pdf Tool for WordPress: from n/a through 1.20.18.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Deserialization of Untrusted Data vulnerability in E2Pdf.Com E2Pdf – Export To Pdf Tool for WordPress.This issue affects E2Pdf – Export To Pdf Tool for WordPress: from n/a through 1.20.18.
Explanation of Vulnerability in Simple Terms
The E2Pdf plugin for WordPress versions up to 1.20.18 contains a deserialization vulnerability that allows authenticated administrators to execute arbitrary PHP code on the site. An attacker with admin privileges can craft malicious serialized data that, when processed by the plugin, runs their own code with full site access. This requires high-level access and is not exploitable by unauthenticated users or lower-privileged accounts.
What an attacker can do
Run arbitrary PHP code on the site with full administrative privileges.
Potential impact on your site
A compromised admin account can fully compromise the site, including data theft, malware injection, and site takeover.
Conditions required to exploit
Attacker must have WordPress administrator account access; no user interaction required.
Key dates
External resources
Related vulnerabilities