CVE-2026-4073 | dougblackjr pdfl.io Plugin up to 1.0.5 on WordPress Shortcode output_shortcode text cross site scripting
A vulnerability was found in dougblackjr pdfl.io Plugin up to 1.0.5 on WordPress. It has been declared as problematic. Impacted is the function output_shortcode of the component Shortcode Handler. Executing a manipulation of the argument text can lead to cross site scripting.
This vulnerability is tracked as CVE-2026-4073. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.