CVE-2025-14793

DK PDF – WordPress PDF Generator <= 2.3.0 - Authenticated (Author+) Server-Side Request Forgery

The DK PDF – WordPress PDF Generator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.3.0 via the 'addContentToMpdf' function. This makes it possible for authenticated attackers, author level and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.


We have discovered 1,506 live websites that are affected by CVE-2025-14793.

Run a Free Instant Scan




Affected Software

Product  Dk Pdf
Category Wordpress Plugins
Vulnerable Domains1,506 live websites (100% of Dk Pdf install base)
Vulnerable Versions
  • from 0 through 2.3
Vulnerable Versions Count12 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-918 Server-Side Request Forgery (SSRF)



Details

  • Published - Jan 16, 2026
  • Updated - Jan 16, 2026

Credits

  • Athiwat Tiprasaharn (finder)
  • Peerapat Samatathanyakorn (finder)

Website Distribution by Country

Number of websites using CVE-2025-14793
United States312 websites



Germany268 websites
France134 websites
Italy95 websites
Poland90 websites
Switzerland56 websites
GB56 websites
Spain54 websites
Netherlands49 websites
Russia29 websites

Website Distribution by TLD

Number of websites using CVE-2025-14793
.com441 websites
.de176 websites
.org114 websites
.fr73 websites
.it71 websites
.pl66 websites
.ch44 websites
.nl39 websites
.net33 websites
.es25 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-14793

Top websites that are affected by CVE-2025-14793. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.ca Canada**,***
***************.org Netherlands**,***
************.fr France**,***
**************.de United States**,***
****.org Germany**,***
****************.***.au Australia**,***
*******.es Spain***,***
*********.****.org United States***,***
****.at Germany***,***
******.*********.es Spain***,***
See full domain list

FAQ

CVE-2025-14793 is Server-Side Request Forgery (SSRF) in Dk Pdf
A total of 1,506 websites have been identified as vulnerable to CVE-2025-14793, based on global website indexing conducted by WebTechSurvey.
The Dk Pdf is affected by the CVE-2025-14793 vulnerability.
Dk Pdf versions up to and including 2.3 are vulnerable to CVE-2025-14793.