Sceawere
Vulnerability Detail
CVE-2026-39719UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated SSRF in PDF Smart Viewer
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 16h ago
- Vendor
- DeKnows
- Product
- PDF Smart Viewer for Elementor
- Attack Type
- CWE-918 Server-Side Request Forgery (SSRF)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-06T09:17:44.077Z",
"pubdate": "2026-10-06T09:17:44.077Z",
"executiveSummary": "The PDF Smart Viewer for Elementor plugin, in versions 1.0.4 and below, contains an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. This security flaw allows unauthenticated remote attackers to force the underlying web server to execute arbitrary HTTP requests to unintended destinations.\nThe vulnerability arises from improper validation of user-supplied input used in server-side request mechanisms, which facilitates the retrieval of internal resources or access to services within the internal network that are typically protected by perimeter firewalls.\nThe impact of this vulnerability is significant, as it enables attackers to perform reconnaissance on internal infrastructure, interact with internal APIs, or potentially bypass access controls on local network resources. Exploitation does not require authentication, making it accessible to any external entity capable of reaching the web server.\nGiven the nature of SSRF, the risk includes unauthorized data exfiltration, information disclosure, and potential lateral movement within the hosting environment. Organizations utilizing this plugin are advised to restrict exposure or apply available updates immediately if provided by the vendor.",
"technicalDetails": "The root cause of the SSRF vulnerability in PDF Smart Viewer for Elementor <= 1.0.4 lies in the failure of the application to adequately sanitize or validate parameters passed to functions responsible for fetching remote PDF content. When the plugin processes a request to render or display a document, it improperly handles input that determines the source URL of the target file.\nIn a standard attack flow, an unauthenticated attacker transmits a crafted HTTP request to a specific endpoint exposed by the plugin. By injecting a malicious URI—typically pointing to local loopback addresses (127.0.0.1), internal service metadata endpoints (e.g., cloud environment metadata services like 169.254.169.254), or internal network assets—the attacker compels the server to initiate an outbound request on their behalf.\nThe vulnerable component performs a server-side fetch without verifying the destination host against an allowlist or implementing strict protocol filtering. Consequently, the server acts as a proxy for the attacker's request, bypassing network-level access controls that would otherwise prevent direct access to sensitive internal infrastructure. This effectively converts the plugin into a relay for the attacker's malicious traffic.\nExploitation is trivial due to the lack of authentication or CSRF tokens protecting the vulnerable endpoint. An attacker can use this behavior to perform port scanning of the internal network, extract sensitive configuration files or environment variables if the server-side request can reach internal management interfaces, or perform denial-of-service (DoS) attacks by flooding internal endpoints.\nThe impact is magnified in cloud-hosted environments where metadata services may reside at predictable addresses. By coercing the server to query these endpoints, an attacker may retrieve identity credentials or sensitive instance metadata. Post-exploitation activities involve using these retrieved credentials or insights to further compromise the web application host or the associated cloud infrastructure, leading to a full system or network compromise."
}