Extension WordPress

Vulnérabilités Fancy Product Designer

Cette page rassemble les failles publiées pour Fancy Product Designer, leurs plages de versions affectées et les correctifs signalés dans la base locale.

16Vulnérabilités
3Critiques
16Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Fancy Product Designer

16 fiches

CVE-2025-13439 Moyenne · 5,9
Fancy Product Designer

Fancy Product Designer | WooCommerce WordPress <= 6.4.8 – Unauthenticated Information Disclosure and PHAR Deserialization via 'url' Parameter

The Fancy Product Designer plugin for WordPress is vulnerable to Information Disclosure and PHAR Deserialization in all versions up to, and including, 6.4.8. This is due to insufficient validation of user-supplied input in the 'url' parameter of the…

Versions affectées

*-6.4.8

Correctif

6.5.0

Publication

15/12/2025

CVE-2025-15526 Moyenne · 5,3
Fancy Product Designer

Fancy Product Designer | WooCommerce WordPress <= 6.4.8 – Unauthenticated Full Path Disclosure via 'pdf' Parameter

The Fancy Product Designer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 6.4.8. This is due to improper error handling in the PDF upload functionality that exposes server filesystem paths…

Versions affectées

*-6.4.8

Correctif

6.5.0

Publication

15/12/2025

CVE-2025-13231 Moyenne · 6,5
Fancy Product Designer

Fancy Product Designer | WooCommerce WordPress <= 6.4.8 – Unauthenticated Server-Side Request Forgery via Race Condition

The Fancy Product Designer plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.4.8. This is due to a time-of-check/time-of-use (TOCTOU) race condition in the 'url' parameter of the fpd_custom_uplod_file AJAX…

Versions affectées

*-6.4.8

Correctif

6.5.0

Publication

15/12/2025

CVE-2025-12570 Élevée · 7,2
Fancy Product Designer

Fancy Product Designer <= 6.4.8 – Unauthenticated Stored Cross-Site Scripting via SVG File Upload

The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping in the data-to-image.php and pdf-to-image.php…

Versions affectées

*-6.4.8

Correctif

6.5.0

Publication

11/12/2025

CVE-2024-0904 Moyenne · 4,4
Fancy Product Designer

Fancy Product Designer < 6.1.81 – Authenticated (Admin+) Stored Cross-Site Scripting via License Field

The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to 6.1.81 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

Versions affectées

[*, 6.1.81)

Correctif

6.1.81

Publication

15/04/2024

CVE-2024-0902 Moyenne · 4,4
Fancy Product Designer

Fancy Product Designer < 6.1.81 – Authenticated (Admin+) Stored Cross-Site Scripting via Product Title

The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to 6.1.81 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

Versions affectées

[*, 6.1.81)

Correctif

6.1.81

Publication

25/03/2024

CVE-2021-4334 Élevée · 8,8
Fancy Product Designer

Fancy Product Designer <= 4.6.9 – Insufficient Authorization to Arbitrary Options Update via fpd_update_options

The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a missing capability check on the fpd_update_options function in versions up to, and including, 4.6.9. This makes it possible for authenticated…

Versions affectées

*-4.6.9

Correctif

4.7.0

Publication

05/04/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités