WordPress security by component
E2Pdf – Export Pdf Tool for WordPress
Plugin description
E2Pdf – Export Pdf Tool for WordPress is a WordPress component with 13 published CVE records in this archive. The latest tracked vulnerability was published Jun 18, 2026; the highest CVE/CNA score is 8.8.
Plugin slug:
e2pdfLatest vulnerability
CVE-2026-12407: E2Pdf – Export Pdf Tool for WordPress: A security weakness
E2Pdf – Export Pdf Tool for WordPress is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.32.26.
| Safe version |
|
||
|---|---|---|---|
| Jun 18, 2026 |
CVE-2026-12407
E2Pdf – Export Pdf Tool for WordPress: A security weakness
E2Pdf – Export Pdf Tool for WordPress is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.32.26.
|
> 1.32.26 |
CVE8.8
NVDPending
|
| Jun 01, 2026 |
CVE-2026-42681
e2pdf: Cross-site scripting
e2pdf is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.32.14.
|
1.32.15 |
CVE7.1
NVDPending
|
| May 08, 2026 |
CVE-2026-7650
E2Pdf – Export Pdf Tool for WordPress: Cross-site scripting
E2Pdf – Export Pdf Tool for WordPress is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.32.17.
|
> 1.32.17 |
CVE6.4
NVDPending
|
| Mar 13, 2026 |
CVE-2026-32442
e2pdf: A security weakness
e2pdf is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.0
NVDPending
|
| Oct 22, 2025 |
CVE-2025-62068
e2pdf: Cross-site scripting
e2pdf is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Nov 01, 2024 |
CVE-2024-37415
e2pdf: A security weakness
e2pdf is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Aug 18, 2024 |
CVE-2024-43318
e2pdf: Cross-site scripting
e2pdf is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Apr 15, 2024 |
CVE-2024-31373
e2pdf: Cross-site request forgery
e2pdf is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Dec 28, 2023 |
CVE-2023-50849
E2Pdf – Export To Pdf Tool for WordPress: SQL injection
E2Pdf – Export To Pdf Tool for WordPress is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.6
NVD7.2
|
| Dec 19, 2023 |
CVE-2023-46154
E2Pdf – Export To Pdf Tool for WordPress: Code execution
E2Pdf – Export To Pdf Tool for WordPress is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE6.6
NVD7.2
|
| Dec 15, 2023 |
CVE-2023-6826
E2Pdf: Dangerous file upload
E2Pdf is affected by dangerous file upload. Exploitation requires an authenticated WordPress account. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE7.2
NVD7.2
|
| Oct 31, 2023 |
CVE-2023-5229
E2Pdf: Cross-site scripting
E2Pdf is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|
| Mar 07, 2022 |
CVE-2022-0535
E2Pdf: Cross-site scripting
E2Pdf is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|