CVE-2026-12124 (GCVE-0-2026-12124)
Vulnerability from cvelistv5
Published
2026-07-28 05:39
Modified
2026-07-28 13:29
CWE
Summary
The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the serveTemplatePdfAjax() function and the serveTemplatePdf() REST route (which is registered with `permission_callback => '__return_true'`) in versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to download stored template PDFs — which may contain customer PII, invoice, order, and certificate data — by requesting the publicly registered admin-ajax action `pdfdraft_embed_pdf` or the REST endpoint `/wp-json/pdfdraft/v1/embed-pdf/templates/{slug}/pdf` with a known or guessable design slug, bypassing the plugin's own .
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-12124",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-07-28T13:29:16.287353Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-07-28T13:29:30.785Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "PDFDraft \u2013 Drag \u0026 Drop PDF Builder, PDF Viewer, Embed \u0026 Download PDF, Certificate \u0026 Invoice Designer",
          "vendor": "wpeverest",
          "versions": [
            {
              "lessThanOrEqual": "1.1.0",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "sl4x0"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "The PDFDraft \u2013 Drag \u0026 Drop PDF Builder, PDF Viewer, Embed \u0026 Download PDF, Certificate \u0026 Invoice Designer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the serveTemplatePdfAjax() function and the serveTemplatePdf() REST route (which is registered with `permission_callback =\u003e \u0027__return_true\u0027`) in versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to download stored template PDFs \u2014 which may contain customer PII, invoice, order, and certificate data \u2014 by requesting the publicly registered admin-ajax action `pdfdraft_embed_pdf` or the REST endpoint `/wp-json/pdfdraft/v1/embed-pdf/templates/{slug}/pdf` with a known or guessable design slug, bypassing the plugin\u0027s own ."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-862",
              "description": "CWE-862 Missing Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-07-28T05:39:41.443Z",
        "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "shortName": "Wordfence"
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3cb869dd-c8cf-4849-a13f-6c8cf1c196b6?source=cve"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/pdfdraft/trunk/src/EmbedPdf.php#L448"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/pdfdraft/trunk/src/EmbedPdf.php#L418"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/pdfdraft/trunk/src/EmbedPdf.php#L60"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/pdfdraft/trunk/src/EmbedPdf.php#L44"
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3621033%40pdfdraft\u0026new=3621033%40pdfdraft"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-06-17T08:38:55.000Z",
          "value": "Vendor Notified"
        },
        {
          "lang": "en",
          "time": "2026-07-27T16:42:46.000Z",
          "value": "Disclosed"
        }
      ],
      "title": "PDFDraft \u003c= 1.1.0 - Missing Authorization to Unauthenticated Sensitive PDF Disclosure via \u0027slug\u0027 Parameter"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
    "assignerShortName": "Wordfence",
    "cveId": "CVE-2026-12124",
    "datePublished": "2026-07-28T05:39:41.443Z",
    "dateReserved": "2026-06-12T15:13:30.625Z",
    "dateUpdated": "2026-07-28T13:29:30.785Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2026-12124\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"yes\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2026-07-28T13:29:16.287353Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2026-07-28T13:29:23.404Z\"}}], \"cna\": {\"title\": \"PDFDraft \u003c= 1.1.0 - Missing Authorization to Unauthenticated Sensitive PDF Disclosure via \u0027slug\u0027 Parameter\", \"credits\": [{\"lang\": \"en\", \"type\": \"finder\", \"value\": \"sl4x0\"}], \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 5.3, \"baseSeverity\": \"MEDIUM\", \"vectorString\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N\"}}], \"affected\": [{\"vendor\": \"wpeverest\", \"product\": \"PDFDraft \\u2013 Drag \u0026 Drop PDF Builder, PDF Viewer, Embed \u0026 Download PDF, Certificate \u0026 Invoice Designer\", \"versions\": [{\"status\": \"affected\", \"version\": \"0\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"1.1.0\"}], \"defaultStatus\": \"unaffected\"}], \"timeline\": [{\"lang\": \"en\", \"time\": \"2026-06-17T08:38:55.000Z\", \"value\": \"Vendor Notified\"}, {\"lang\": \"en\", \"time\": \"2026-07-27T16:42:46.000Z\", \"value\": \"Disclosed\"}], \"references\": [{\"url\": \"https://www.wordfence.com/threat-intel/vulnerabilities/id/3cb869dd-c8cf-4849-a13f-6c8cf1c196b6?source=cve\"}, {\"url\": \"https://plugins.trac.wordpress.org/browser/pdfdraft/trunk/src/EmbedPdf.php#L448\"}, {\"url\": \"https://plugins.trac.wordpress.org/browser/pdfdraft/trunk/src/EmbedPdf.php#L418\"}, {\"url\": \"https://plugins.trac.wordpress.org/browser/pdfdraft/trunk/src/EmbedPdf.php#L60\"}, {\"url\": \"https://plugins.trac.wordpress.org/browser/pdfdraft/trunk/src/EmbedPdf.php#L44\"}, {\"url\": \"https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3621033%40pdfdraft\u0026new=3621033%40pdfdraft\"}], \"descriptions\": [{\"lang\": \"en\", \"value\": \"The PDFDraft \\u2013 Drag \u0026 Drop PDF Builder, PDF Viewer, Embed \u0026 Download PDF, Certificate \u0026 Invoice Designer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the serveTemplatePdfAjax() function and the serveTemplatePdf() REST route (which is registered with `permission_callback =\u003e \u0027__return_true\u0027`) in versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to download stored template PDFs \\u2014 which may contain customer PII, invoice, order, and certificate data \\u2014 by requesting the publicly registered admin-ajax action `pdfdraft_embed_pdf` or the REST endpoint `/wp-json/pdfdraft/v1/embed-pdf/templates/{slug}/pdf` with a known or guessable design slug, bypassing the plugin\u0027s own .\"}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-862\", \"description\": \"CWE-862 Missing Authorization\"}]}], \"providerMetadata\": {\"orgId\": \"b15e7b5b-3da4-40ae-a43c-f7aa60e62599\", \"shortName\": \"Wordfence\", \"dateUpdated\": \"2026-07-28T05:39:41.443Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2026-12124\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-07-28T13:29:30.785Z\", \"dateReserved\": \"2026-06-12T15:13:30.625Z\", \"assignerOrgId\": \"b15e7b5b-3da4-40ae-a43c-f7aa60e62599\", \"datePublished\": \"2026-07-28T05:39:41.443Z\", \"assignerShortName\": \"Wordfence\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…