PT-2026-95284 · WordPress · Printcart Web To Print Product Designer

·

CVE-2026-14323

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Printcart Web to Print Product Designer for WooCommerce versions prior to 2.8.6
Description This issue involves a Directory Traversal flaw that allows unauthenticated attackers to read arbitrary files on the server, potentially exposing sensitive information. The flaw is triggered via the mockups parameter. Attackers can obtain a valid nonce through the nbd check use logged in AJAX endpoint, which provides a nbdesigner-get-data nonce to any visitor. Furthermore, the security check is completely bypassed if the NBDESIGNER ENABLE NONCE constant is disabled.
Recommendations Update Printcart Web to Print Product Designer for WooCommerce to version 2.8.6 or later. Restrict access to the mockups parameter to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14323

Affected Products

Printcart Web To Print Product Designer