PT-2026-64830 · WordPress · Printcart Web To Print Product Designer
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Printcart Web to Print Product Designer for WooCommerce WordPress plugin versions prior to 2.5.3
Description
An issue exists where the software fails to restrict user-supplied URLs before fetching them server-side and does not enforce valid authorization checks. This allows unauthenticated attackers to read arbitrary local files, such as configuration files containing secret keys and database credentials, and to perform server-side requests to internal resources.
Recommendations
Update Printcart Web to Print Product Designer for WooCommerce WordPress plugin to version 2.5.3 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Printcart Web To Print Product Designer