PatchSiren

pdfl.io CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM pdfl.io CVE published 2026-04-08

CVE-2026-4073

The CVE record for CVE-2026-4073 was published on 2026-04-08T10:16:01.777Z and has not been modified since then. The NVD entry is currently Deferred. This vulnerability affects the pdfl.io plugin for WordPress, specifically versions up to and including 1.0.5. The vulnerability class is Stored Cross-Site Scripting via the 'pdflio' shortcode. The likely operational impact includes authenticated attackers in [truncated]