Showing 3 vulnerabilities on this page for fancy_product_designer

Signals CISA KEV Ransomware Nuclei
radykal vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Fancy Product Designer < 6.1.8 - Reflected Cross Site Scripting

The Fancy Product Designer WordPress plugin before 6.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against unauthenticated and admin-level users

CWE-79Apr 26, 2024
CVSS6.3v3.1EPSS0.462%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Fancy Product Designer < 6.1.5 - Admin+ SQL Injection

The Fancy Product Designer WordPress plugin before 6.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by adminstrators.

CWE-89Mar 18, 2024
CVSS6.5v3.1EPSS0.641%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Fancy Product Designer < 4.6.9 - Unauthenticated Arbitrary File Upload and RCE

The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.

CWE-434Jun 21, 20211 related artifact
CVSS9.8v3.1EPSS47.1%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX