CVE · Medium

CVE-2026-27416 — PDF Poster – let visitors read PDFs without leaving the page [pdf-poster] < 2.5.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-27416 PDF Poster – let visitors read PDFs without leaving the page [pdf-poster] < 2.5.0 Missing Authorization Medium 5.3 < 2.5.0 2.5.0 2026-05-07

CVE-2026-27416

The PDF Poster plugin for WordPress suffers from a capability oversight. In versions prior to or equal to 2.4.1, a specific function lacks required authentication checks. This allows malicious users to execute an illicit operation without needing proper credentials.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.