CVE-2024-0365
- EPSS 0.64%
- Veröffentlicht 18.03.2024 19:15:06
- Zuletzt bearbeitet 05.05.2025 15:15:56
The Fancy Product Designer WordPress plugin before 6.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by adminstrators.
CVE-2021-4334
- EPSS 0.67%
- Veröffentlicht 20.10.2023 08:15:11
- Zuletzt bearbeitet 08.04.2026 19:17:40
The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a missing capability check on the fpd_update_options function in versions up to, and including, 4.6.9. This makes it possible for authen...
CVE-2021-4335
- EPSS 0.4%
- Veröffentlicht 20.10.2023 07:15:14
- Zuletzt bearbeitet 08.04.2026 18:17:13
The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized access to data and modification of plugin settings due to a missing capability check on multiple AJAX functions in versions up to, and including, 4.6.9. This makes it possi...
CVE-2021-4096
- EPSS 0.59%
- Veröffentlicht 19.04.2022 21:15:13
- Zuletzt bearbeitet 21.11.2024 06:36:53
The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import class that makes it possible for attackers to upload malicious files that could be used to gain webshell access to a server in versio...
CVE-2021-4134
- EPSS 1.44%
- Veröffentlicht 16.02.2022 17:15:11
- Zuletzt bearbeitet 21.11.2024 06:36:58
The Fancy Product Designer WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the ID parameter found in the ~/inc/api/class-view.php file which allows attackers with administrative level permissions t...
CVE-2021-24370
- EPSS 47.09%
- Veröffentlicht 21.06.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 05:52:55
The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.