Radykal

Fancy Product Designer

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.64%
  • Veröffentlicht 18.03.2024 19:15:06
  • Zuletzt bearbeitet 05.05.2025 15:15:56

The Fancy Product Designer WordPress plugin before 6.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by adminstrators.

  • EPSS 0.67%
  • Veröffentlicht 20.10.2023 08:15:11
  • Zuletzt bearbeitet 08.04.2026 19:17:40

The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a missing capability check on the fpd_update_options function in versions up to, and including, 4.6.9. This makes it possible for authen...

  • EPSS 0.4%
  • Veröffentlicht 20.10.2023 07:15:14
  • Zuletzt bearbeitet 08.04.2026 18:17:13

The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized access to data and modification of plugin settings due to a missing capability check on multiple AJAX functions in versions up to, and including, 4.6.9. This makes it possi...

  • EPSS 0.59%
  • Veröffentlicht 19.04.2022 21:15:13
  • Zuletzt bearbeitet 21.11.2024 06:36:53

The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import class that makes it possible for attackers to upload malicious files that could be used to gain webshell access to a server in versio...

Exploit
  • EPSS 1.44%
  • Veröffentlicht 16.02.2022 17:15:11
  • Zuletzt bearbeitet 21.11.2024 06:36:58

The Fancy Product Designer WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the ID parameter found in the ~/inc/api/class-view.php file which allows attackers with administrative level permissions t...

Exploit
  • EPSS 47.09%
  • Veröffentlicht 21.06.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 05:52:55

The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.