PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer
PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 28, 2026; the highest CVE/CNA score is 5.3.
pdfdraftCVE-2026-12124: PDFDraft exposes stored template PDFs without authentication
PDFDraft through 1.1.0 registers the pdfdraft_embed_pdf admin-ajax action for unauthenticated callers and exposes GET /wp-json/pdfdraft/v1/embed-pdf/templates/{slug}/pdf with permission_callback set to __return_true. serveTemplatePdfAjax() and serveTemplatePdf() accept a known or guessable design slug, map it to projects/{slug}.pdf in plugin storage, and return the file without verifying a capability or access token. Stored templates can contain customer PII, invoices, orders or certificate data.
| Safe version |
|
||
|---|---|---|---|
| Jul 28, 2026 |
CVE-2026-12124
PDFDraft exposes stored template PDFs without authentication
PDFDraft through 1.1.0 registers the pdfdraft_embed_pdf admin-ajax action for unauthenticated callers and exposes GET /wp-json/pdfdraft/v1/embed-pdf/templates/{slug}/pdf with permission_callback set to __return_true. serveTemplatePdfAjax() and serveTemplatePdf() accept a known or guessable design slug, map it to projects/{slug}.pdf in plugin storage, and return the file without verifying a capability or access token. Stored templates can contain customer PII, invoices, orders or certificate data.
|
> 1.1.0 |
CVE5.3
NVDPending
|