{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/save-as-pdf-plugin--4.6.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pdfcrowd:save_as_pdf_plugin:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-92807"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Save as PDF Plugin (\u003c= 4.6.1)"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","wordpress","cve-2026-92807"],"_cs_type":"advisory","_cs_vendors":["PDFCrowd"],"content_html":"\u003cp\u003eThe Save as PDF Plugin by PDFCrowd for WordPress (all versions up to and including 4.6.1) contains an arbitrary function invocation vulnerability in the \u003ccode\u003esave_as_pdf_pdfcrowd()\u003c/code\u003e function. The flaw exists because the plugin fails to sanitize or validate shortcode attributes passed to the \u003ccode\u003eeval_shortcode()\u003c/code\u003e function. Specifically, the \u003ccode\u003epdf_created_callback\u003c/code\u003e attribute is copied into an options array, which is then encrypted using AES and embedded into the rendered HTML output.\u003c/p\u003e\n\u003cp\u003eWhen this button is accessed, the encrypted blob is POSTed to the \u003ccode\u003ewp_ajax_nopriv_save_as_pdf_pdfcrowd\u003c/code\u003e endpoint. The server decrypts this blob and invokes the value of \u003ccode\u003e$options['pdf_created_callback']\u003c/code\u003e as a PHP callable at line 1722 without verifying if the target is a valid callable or checking user capabilities. Because the server itself performs the encryption during page rendering, an attacker with Contributor access can inject a malicious callback into a post or page, receive the valid encrypted blob from the server, and then trigger the arbitrary function via an unauthenticated request. This allows for the disclosure of sensitive plugin data like API keys or usernames.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated users with Contributor-level access and above to execute arbitrary PHP functions or static class methods on the underlying WordPress server. This leads to the disclosure of sensitive configuration data, including PDFCrowd API credentials, or potential further server-side abuse. Given the popularity of WordPress plugins, this vulnerability presents a significant risk to any site using vulnerable versions of this plugin.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch CVE-2026-92807 by updating the Save as PDF Plugin to the latest available version beyond 4.6.1 immediately.\u003c/li\u003e\n\u003cli\u003eImplement an allowlist for the \u003ccode\u003epdf_created_callback\u003c/code\u003e parameter in the plugin configuration if an immediate patch is not possible.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rules below to monitor for suspicious AJAX requests to the vulnerable endpoint and tune for your environment.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-19T06:09:18Z","date_published":"2026-09-19T06:09:18Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-92807/","summary":"The Save as PDF Plugin for WordPress up to version 4.6.1 is vulnerable to arbitrary function invocation via the pdf_created_callback shortcode attribute, allowing authenticated Contributor-level users to trigger sensitive data disclosure.","title":"CVE-2026-92807: Arbitrary Function Invocation in Save as PDF Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-92807/"}],"language":"en","title":"CraftedSignal Threat Feed - Save as PDF Plugin (\u003c= 4.6.1)","version":"https://jsonfeed.org/version/1.1"}