CVE-2026-32473: WordPress PDF Smart Viewer for Elementor plugin <= 1.0.4 - Server Side Request Forgery (SSRF) vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions.
Affected Software
1 affected component
wordpress/PDF Smart Viewer for Elementor<=1.0.4
Event History
Aug 18, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed to this vulnerability?
Any site running PDF Smart Viewer for Elementor version 1.0.4 or earlier is affected. The issue is reachable over the network and does not require authentication or user interaction.
2
What does an attacker need to exploit it?
An attacker only needs network access to the vulnerable site; no WordPress account or elevated privileges are required. Successful exploitation can cause the server to make attacker-influenced requests, with low confidentiality and integrity impact reflected in the supplied severity vector.