Radykal Fancy Product Designer vulnerabilities
15 known vulnerabilities affecting radykal/fancy_product_designer.
Total CVEs
15
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH3MEDIUM9UNKNOWN2
Vulnerabilities
Page 1 of 1
CVE-2025-15526MEDIUMCVSS 5.3≤ 6.4.82026-01-16
CVE-2025-15526 [MEDIUM] CWE-209 CVE-2025-15526: The Fancy Product Designer plugin for WordPress is vulnerable to Full Path Disclosure in all version
The Fancy Product Designer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 6.4.8. This is due to improper error handling in the PDF upload functionality that exposes server filesystem paths and stack traces in error messages. This makes it possible for unauthenticated attackers to retrieve the full pa
cvelistv5nvd
CVE-2025-13231MEDIUMCVSS 6.5≤ 6.4.82025-12-16
CVE-2025-13231 [MEDIUM] CWE-362 CVE-2025-13231: The Fancy Product Designer plugin for WordPress is vulnerable to Server-Side Request Forgery in all
The Fancy Product Designer plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.4.8. This is due to a time-of-check/time-of-use (TOCTOU) race condition in the 'url' parameter of the fpd_custom_uplod_file AJAX action. The plugin validates the URL by calling getimagesize() first, then later retrieves
cvelistv5nvd
CVE-2025-13439MEDIUMCVSS 5.9≤ 6.4.82025-12-16
CVE-2025-13439 [MEDIUM] CWE-200 CVE-2025-13439: The Fancy Product Designer plugin for WordPress is vulnerable to Information Disclosure and PHAR Des
The Fancy Product Designer plugin for WordPress is vulnerable to Information Disclosure and PHAR Deserialization in all versions up to, and including, 6.4.8. This is due to insufficient validation of user-supplied input in the 'url' parameter of the 'fpd_custom_uplod_file' AJAX action, which flows directly into the 'getimagesize' function without sa
cvelistv5nvd
CVE-2025-12570HIGHCVSS 7.2≤ 6.4.82025-12-12
CVE-2025-12570 [HIGH] CWE-79 CVE-2025-12570: The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG
The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping in the data-to-image.php and pdf-to-image.php files. This makes it possible for unauthenticated attackers to inject arbitrary web scripts
cvelistv5nvd
CVE-2024-51919UNKNOWN≤ 6.4.32025-01-21
CVE-2024-51919 CWE-434 CVE-2024-51919: Unrestricted Upload of File with Dangerous Type vulnerability in radykal Fancy Product Designer fanc
Unrestricted Upload of File with Dangerous Type vulnerability in radykal Fancy Product Designer fancy-product-designer.This issue affects Fancy Product Designer: from n/a through <= 6.4.3.
cvelistv5nvd
CVE-2024-51818UNKNOWN≤ 6.4.32025-01-21
CVE-2024-51818 CWE-89 CVE-2024-51818: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in radykal Fancy Product Designer fancy-product-designer.This issue affects Fancy Product Designer: from n/a through <= 6.4.3.
cvelistv5nvd
CVE-2024-0904MEDIUMCVSS 5.9fixed in 6.1.812024-05-06
CVE-2024-0904 [MEDIUM] CWE-79 CVE-2024-0904: The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its s
The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
nvd
CVE-2024-0905MEDIUMCVSS 6.3fixed in 6.1.82024-04-26
CVE-2024-0905 [MEDIUM] CWE-79 CVE-2024-0905: The Fancy Product Designer WordPress plugin before 6.1.8 does not sanitise and escape a parameter be
The Fancy Product Designer WordPress plugin before 6.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against unauthenticated and admin-level users
nvd
CVE-2024-0902MEDIUMCVSS 4.8≤ 6.1.82024-04-15
CVE-2024-0902 [MEDIUM] CWE-79 CVE-2024-0902: The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its s
The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
nvd
CVE-2024-0365MEDIUMCVSS 6.5fixed in 6.1.52024-03-18
CVE-2024-0365 [MEDIUM] CWE-89 CVE-2024-0365: The Fancy Product Designer WordPress plugin before 6.1.5 does not properly sanitise and escape a par
The Fancy Product Designer WordPress plugin before 6.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by adminstrators.
nvd
CVE-2021-4334HIGHCVSS 8.8fixed in 4.7.0≤ 4.6.92023-10-20
CVE-2021-4334 [HIGH] CWE-285 CVE-2021-4334: The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site o
The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a missing capability check on the fpd_update_options function in versions up to, and including, 4.6.9. This makes it possible for authenticated attackers with subscriber-level permissions to modify site options, including setting the default
cvelistv5nvd
CVE-2021-4335MEDIUMCVSS 6.3fixed in 4.7.0≤ 4.6.92023-10-20
CVE-2021-4335 [MEDIUM] CWE-285 CVE-2021-4335: The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized access to data and mod
The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized access to data and modification of plugin settings due to a missing capability check on multiple AJAX functions in versions up to, and including, 4.6.9. This makes it possible for authenticated attackers with subscriber-level permissions to modify plugin settings, including
cvelistv5nvd
CVE-2021-4096HIGHCVSS 8.8≤ 4.7.52022-04-19
CVE-2021-4096 [HIGH] CWE-352 CVE-2021-4096: The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the
The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import class that makes it possible for attackers to upload malicious files that could be used to gain webshell access to a server in versions up to, and including, 4.7.5.
nvd
CVE-2021-4134MEDIUMCVSS 4.9fixed in 4.7.52022-02-16
CVE-2021-4134 [MEDIUM] CWE-89 CVE-2021-4134: The Fancy Product Designer WordPress plugin is vulnerable to SQL Injection due to insufficient escap
The Fancy Product Designer WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the ID parameter found in the ~/inc/api/class-view.php file which allows attackers with administrative level permissions to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 4.7.4.
nvd
CVE-2021-24370CRITICALCVSS 9.8ExploitedPoCfixed in 4.6.92021-06-21
CVE-2021-24370 [CRITICAL] CWE-434 CVE-2021-24370: The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload
The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.
nvd