PT-2026-103098 · WordPress · Product Designer App
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Product Designer App plugin for WordPress versions prior to 1.1.4
Description
A Directory Traversal issue exists where unauthenticated attackers can read arbitrary files from the server, potentially exposing sensitive information. This is possible via the
svg parameter. The authentication mechanism for the affected endpoint relies on a nonce and token that are exposed as JavaScript globals on any page using the [pdapp-studio-page] shortcode, allowing anonymous visitors to obtain them.Recommendations
Update the Product Designer App plugin for WordPress to version 1.1.4 or later.
As a temporary mitigation, avoid using the
svg parameter in the affected endpoint.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Product Designer App