CVE-2026-12407
oleksandrz E2Pdf – Export Pdf Tool for WordPress
The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.32.26. This is due to the screen_action() function lacking a dedicated capability check and nonce verification — when invoked via the ?action=screen routing path the controller's index_action() nonce gate is bypassed entirely — while reading an attacker-controlled option name and value from $_POST['wp_screen_options'] and passing them directly to update_option() with no allowlist, relying solely on the page-level e2pdf_templates capability which the plugi...
- CVSS
- 8.8
- EPSS
- 0.38% 30.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.18