radykal Vulnerabilities and Affected Products
Vulnerabilities associated with fancy_product_designer.
Products
Clear product- Fancy Product Designer8 vulnerabilities
- fancy_product_designer3 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-0905MEDIUM | Fancy Product Designer < 6.1.8 - Reflected Cross Site ScriptingThe Fancy Product Designer WordPress plugin before 6.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against unauthenticated and admin-level users CWE-79Apr 26, 2024 | CVSS6.3v3.1 | EPSS0.462% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-0365MEDIUM | Fancy Product Designer < 6.1.5 - Admin+ SQL InjectionThe Fancy Product Designer WordPress plugin before 6.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by adminstrators. CWE-89Mar 18, 2024 | CVSS6.5v3.1 | EPSS0.641% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24370CRITICAL | Fancy Product Designer < 4.6.9 - Unauthenticated Arbitrary File Upload and RCEThe Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution. | CVSS9.8v3.1 | EPSS47.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |