E2Pdf – Export Pdf Tool for WordPress

E2Pdf – Export Pdf Tool for WordPress has 14 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2026; all 14 are fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 4 high. 2026 was the busiest year with 5 disclosures.

The most common weakness is Cross-Site Scripting, behind 6 of the records (43%). Other recurring categories include Missing Authorization, Cross-Site Request Forgery (CSRF).

Every one of the 14 issues recorded for E2Pdf – Export Pdf Tool for WordPress has a vendor fix available, so running the current release closes all known holes.

12 independent researchers contributed these findings, most of them (3) reported by Steven Julian. E2Pdf – Export Pdf Tool for WordPress is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

01234567891020.08.2018Today09.02.20224.8E2Pdf <= 1.16.44 - Stored Cross-Site Scripting CVSS 4.8 · 09.02.202209.10.20234.4e2pdf < 1.20.20 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 09.10.202317.10.20237.2E2Pdf <= 1.20.18 - Authenticated (Administrator+) PHP Object Injection CVSS 7.2 · 17.10.202313.12.20237.2E2Pdf <= 1.20.25 - Authenticated (Administrator+) Arbitrary File Upload CVSS 7.2 · 13.12.202321.12.20236.6E2Pdf <= 1.20.23 - Authenticated(Administrator+) SQL Injection CVSS 6.6 · 21.12.202310.04.20244.3e2pdf <= 1.20.27 - Cross-Site Request Forgery CVSS 4.3 · 10.04.202428.06.20244.3E2Pdf – Export To Pdf Tool for WordPress <= 1.20.27 - Missing Authorization CVSS 4.3 · 28.06.202416.08.20246.4e2pdf <= 1.25.05 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 16.08.202416.10.20256.4e2pdf <= 1.28.09 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 16.10.202504.03.20264.3e2pdf <= 1.28.15 - Missing Authorization CVSS 4.3 · 04.03.202607.05.20266.4E2Pdf – Export Pdf Tool for WordPress <= 1.32.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute CVSS 6.4 · 07.05.202618.05.20266.1E2Pdf – Export Pdf Tool for WordPress <= 1.32.14 - Reflected Cross-Site Scripting CVSS 6.1 · 18.05.202617.06.20268.8E2Pdf <= 1.32.26 - Missing Authorization to Authenticated (Custom+) Arbitrary Option Update / Privilege Escalation via 'screen_action' Parameter CVSS 8.8 · 17.06.202605.08.20268.1E2Pdf – Export Pdf Tool for WordPress <= 1.32.40 - Unauthenticated Local File Inclusion CVSS 8.1 · 05.08.2026

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

14

Get automatic notifications for all E2Pdf – Export Pdf Tool for WordPress vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2026-12407

E2Pdf <= 1.32.26 - Missing Authorization to Authenticated (Custom+) Arbitrary Option Update / Privilege Escalation via 'screen_action' Parameter

Read the full analysis

Vulnerability Records

14 records
2026-08-05 00:00CVE-2026-66710
8.1
High
Noman RiffatYes
2026-06-17 14:55CVE-2026-12407
8.8
High
endyYes
2026-05-18 00:00CVE-2026-42681
6.1
Medium
hhhaiYes
2026-05-07 20:45CVE-2026-7650
6.4
Medium
zaimYes
2026-03-04 00:00CVE-2026-32442
4.3
Medium
Steven JulianYes
2025-10-16 00:00CVE-2025-62068
6.4
Medium
Muhammad Yudha - DJYes
2024-08-16 00:00CVE-2024-43318
6.4
Medium
LVT-tholv2kYes
2024-06-28 00:00CVE-2024-37415
4.3
Medium
Steven JulianYes
2024-04-10 00:00CVE-2024-31373
4.3
Medium
Steven JulianYes
2023-12-21 00:00CVE-2023-50849
6.6
Medium
Muhammad DaffaYes
Showing 1–10 of 14 reports
E2Pdf – Export Pdf Tool for WordPress banner
Latestv1.32.48

E2Pdf – Export Pdf Tool for WordPress

E2Pdf

Author

E2Pdf

4.8(58)
96/100
Last Updated
2026-09-07 (6d ago)
Active Installs
10,000+
Downloads
634,037
Requires WP
5.9+
Requires PHP
5.4+
Tested up to
WP 7.1
Created
2018-08-20 (8y ago)

E2Pdf is the next generation PDF tool for WordPress. This plugin includes: a PDF Document Viewer – Allow visitors to view static or dynamic PDF documents in WordPress. a PDF Document Editor – Create/Edit new and existing PDF documents without leaving WordPress. a PDF Forms Editor – Create/Edit new, existing, and auto-generated PDF Forms from the Dashboard. a PDF Data Injector – Merge data from WordPress pages, posts, or web forms into PDF forms. a Generous Affiliate Program – 90-day cookies. 20% commission paid lifetime for all new payments. Learn all about E2Pdf Documentation | Help Desk | Contact Us PDF DOCUMENT VIEWER: [e2pdf-view] Allows users to view and print PDF documents without leaving your site. Preview dynamically created PDF documents prior to downloading, emailing, or purchasing. PDF DOCUMENT EDITOR: Built-in Create a PDF from a blank document. Upload and edit existing PDF documents. Add/Edit text and images. Auto-generate PDF documents based on a WordPress page or post. PDF FORMS EDITOR: Built-in Create PDF forms from a blank document. Upload and edit existing PDF documents or forms, no need for third-party software. Auto-generate PDF forms based on a WordPress page, post, or web form. Use actions and conditions to create dynamic PDF documents. PDF DATA INJECTOR: Remotely Generated¹ Map WordPress pages or post to PDF fields. Map web forms to PDF form fields. Map signature² fields to PDF form fields. Map images² to PDF form fields. EMAIL PDF OPTIONS Send as email attachment. Send a link in email body to download PDF documents and forms. SAVE DYNAMIC PDF TO SERVER Save form filled PDF documents to static or dynamic folders on your server. Integrations Easily create, populate, and email PDFs using popular form builders and platforms: Caldera Forms: Demo Contact Form 7: Demo Divi Contact Forms: Demo Elementor Forms: Demo Everest Forms: Demo Fluent Forms: Demo Formidable Forms: Demo Forminator Forms: Demo Gravity Forms: Demo JetFormBuilder: Demo MetForm: Demo Ninja Forms PDF: Demo WooCommerce Order / Product : Demo WordPress / Post / Meta / ACF: Demo WPForms: Demo APIs Adobe Sign REST API Terms of Service By continuing to use our plugin you are agreeing to our Terms of Service. Additional Information, Definition and Explaination ¹ Remotely Generated: Due to the complex nature of the PDF file format, dynamic PDF documents are generating remotely with the E2Pdf API at E2Pdf.com. PRIVACY POLICY: We do not collect or store any web form submitted user private data that is sent to the API. ² Selected extension must include the signature field or image field. ³ Beta Integrations: Extensions that are available in the Release Candidate version. History E2Pdf is the new and highly improved iteration of the Formidable PRO2PDF plugin. Originally designed and coded in 2013 out of a need to print dynamic PDF documents from WordPress forms, PRO2PDF provided the automation necessary for a small insurance broker to produce far more business with the same number of employees. Today, the E2Pdf plugin and WordPress extension provide the entire WordPress community with a cost free method of creating dynamic PDF documents – without programming or coding – with one simple shortcode. More information can be found at E2Pdf.com

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C