Medium 6.5
2025-09-22< 4.5.3
Save as PDF <= 4.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Minimum safe version
4.5.6
Update to 4.5.6 or later to address 10 fixable vulnerabilities
Save as PDF <= 4.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Save as PDF Plugin by PDFCrowd <= 4.5.5 - Reflected Cross-Site Scripting via options
CVE-2025-24671
CVE-2024-10891
CVE-2024-37549
CVE-2024-35649
WordPress Save as PDF plugin by Pdfcrowd Plugin < 3.2.0 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-33684
CVE-2024-31930
CVE-2023-40668