CVE-2026-12124 | wpeverest PDFDraft Plugin up to 1.1.0 on WordPress REST Endpoint templates serveTemplatePdfAjax/serveTemplatePdf slug privileges management

SecurityVulns

A vulnerability categorized as problematic has been discovered in wpeverest PDFDraft Plugin up to 1.1.0 on WordPress. Affected by this vulnerability is the function serveTemplatePdfAjax/serveTemplatePdf of the file /wp-json/pdfdraft/v1/embed-pdf/templates of the component REST Endpoint. The manipulation of the argument slug results in improper privilege management.

This vulnerability is known as CVE-2026-12124. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More