plugin

Fancy Product Designer Vulnerabilities

34 known security issues reported for the Fancy Product Designer WordPress plugin. Most recent disclosed Jan 16, 2026.

3 critical 5 high 8 medium

Running Fancy Product Designer on your site? Check whether your installed version is affected.

Scan your site free

Fancy Product Designer [fancy-product-designer] < 6.5.0

unknown

[en] The Fancy Product Designer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 6.4.8. This is due to improper error handling in the PDF upload functionality that exposes server filesystem paths and stack traces in error messages. This makes it possible for unauthenticat...

Affected:
up to 6.5.0
Fixed in:
6.5.0
Disclosed:
Jan 16, 2026

CVE-2025-15526 on NVD →

Fancy Product Designer [fancy-product-designer] < 6.5.0

unknown

[en] The Fancy Product Designer plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 6.4.8. This is due to insufficient validation of user-supplied input in the 'url' parameter of the fpd_custom_uplod_file AJAX action, which flows directly into the getimagesize() function w...

Affected:
up to 6.5.0
Fixed in:
6.5.0
Disclosed:
Dec 16, 2025

CVE-2025-13439 on NVD →

Fancy Product Designer [fancy-product-designer] < 6.5.0

unknown

[en] The Fancy Product Designer plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.4.8. This is due to a time-of-check/time-of-use (TOCTOU) race condition in the 'url' parameter of the fpd_custom_uplod_file AJAX action. The plugin validates the URL by calling getim...

Affected:
up to 6.5.0
Fixed in:
6.5.0
Disclosed:
Dec 16, 2025

CVE-2025-13231 on NVD →

Fancy Product Designer | WooCommerce WordPress <= 6.4.8 - Unauthenticated Server-Side Request Forgery via Race Condition

medium

The Fancy Product Designer plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.4.8. This is due to a time-of-check/time-of-use (TOCTOU) race condition in the 'url' parameter of the fpd_custom_uplod_file AJAX action. The plugin validates the URL by calling getimagesi...

CVSS:
6.5
Affected:
up to 6.4.8
Fixed in:
6.5.0
Disclosed:
Dec 15, 2025

CVE-2025-13231 on NVD →

Fancy Product Designer | WooCommerce WordPress <= 6.4.8 - Unauthenticated Information Disclosure and PHAR Deserialization via 'url' Parameter

medium

The Fancy Product Designer plugin for WordPress is vulnerable to Information Disclosure and PHAR Deserialization in all versions up to, and including, 6.4.8. This is due to insufficient validation of user-supplied input in the 'url' parameter of the 'fpd_custom_uplod_file' AJAX action, which flows directly into the 'ge...

CVSS:
5.9
Affected:
up to 6.4.8
Fixed in:
6.5.0
Disclosed:
Dec 15, 2025

CVE-2025-13439 on NVD →

Fancy Product Designer | WooCommerce WordPress <= 6.4.8 - Unauthenticated Full Path Disclosure via 'pdf' Parameter

medium

The Fancy Product Designer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 6.4.8. This is due to improper error handling in the PDF upload functionality that exposes server filesystem paths and stack traces in error messages. This makes it possible for unauthenticated at...

CVSS:
5.3
Affected:
up to 6.4.8
Fixed in:
6.5.0
Disclosed:
Dec 15, 2025

CVE-2025-15526 on NVD →

Fancy Product Designer [fancy-product-designer] < 6.5.0

unknown

[en] The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping in the data-to-image.php and pdf-to-image.php files. This makes it possible for unauthenticated at...

Affected:
up to 6.5.0
Fixed in:
6.5.0
Disclosed:
Dec 12, 2025

CVE-2025-12570 on NVD →

Fancy Product Designer <= 6.4.8 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload

high

The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping in the data-to-image.php and pdf-to-image.php files. This makes it possible for unauthenticated attacke...

CVSS:
7.2
Affected:
up to 6.4.8
Fixed in:
6.5.0
Disclosed:
Dec 11, 2025

CVE-2025-12570 on NVD →

Fancy Product Designer [fancy-product-designer] < 6.4.4

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Fancy Product Designer. This issue affects Fancy Product Designer: from n/a through 6.4.3.

Affected:
up to 6.4.4
Fixed in:
6.4.4
Disclosed:
Jan 21, 2025

CVE-2024-51818 on NVD →

Fancy Product Designer [fancy-product-designer] < 6.4.4

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Fancy Product Designer. This issue affects Fancy Product Designer: from n/a through 6.4.3.

Affected:
up to 6.4.4
Fixed in:
6.4.4
Disclosed:
Jan 21, 2025

CVE-2024-51919 on NVD →

Fancy Product Designer <= 6.4.3 - Unauthenticated Arbitrary File Upload

critical

The Fancy Product Designer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 6.4.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possi...

CVSS:
9.8
Affected:
up to 6.4.3
Fixed in:
6.4.4
Disclosed:
Jan 3, 2025

CVE-2024-51919 on NVD →

Fancy Product Designer <= 6.4.3 - Unauthenticated SQL Injection

high

The Fancy Product Designer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL...

CVSS:
7.5
Affected:
up to 6.4.3
Fixed in:
6.4.4
Disclosed:
Jan 3, 2025

CVE-2024-51818 on NVD →

Fancy Product Designer [fancy-product-designer] < 6.1.81

unknown

[en] The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 6.1.81
Fixed in:
6.1.81
Disclosed:
May 6, 2024

CVE-2024-0904 on NVD →

Fancy Product Designer <= 6.1.7 - Reflected Cross-Site Scripting

medium

The Fancy Product Designer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 6.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can s...

CVSS:
6.1
Affected:
up to 6.1.7
Fixed in:
6.1.8
Disclosed:
Apr 26, 2024

CVE-2024-0905 on NVD →

Fancy Product Designer [fancy-product-designer] < 6.1.8

unknown

[en] The Fancy Product Designer WordPress plugin before 6.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against unauthenticated and admin-level users

Affected:
up to 6.1.8
Fixed in:
6.1.8
Disclosed:
Apr 26, 2024

CVE-2024-0905 on NVD →

Fancy Product Designer < 6.1.81 - Authenticated (Admin+) Stored Cross-Site Scripting via License Field

medium

The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to 6.1.81 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inje...

CVSS:
4.4
Affected:
up to 6.1.81
Fixed in:
6.1.81
Disclosed:
Apr 15, 2024

CVE-2024-0904 on NVD →

Fancy Product Designer [fancy-product-designer] < 6.1.81

unknown

[en] The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 6.1.81
Fixed in:
6.1.81
Disclosed:
Apr 15, 2024

CVE-2024-0902 on NVD →

Fancy Product Designer < 6.1.81 - Authenticated (Admin+) Stored Cross-Site Scripting via Product Title

medium

The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to 6.1.81 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inje...

CVSS:
4.4
Affected:
up to 6.1.81
Fixed in:
6.1.81
Disclosed:
Mar 25, 2024

CVE-2024-0902 on NVD →

Fancy Product Designer [fancy-product-designer] < 6.1.5

unknown

[en] The Fancy Product Designer WordPress plugin before 6.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by adminstrators.

Affected:
up to 6.1.5
Fixed in:
6.1.5
Disclosed:
Mar 18, 2024

CVE-2024-0365 on NVD →

Fancy Product Designer <= 6.1.4 - Authenticated (Admin+) SQL Injection

critical

The Fancy Product Designer plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 6.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-lev...

CVSS:
9.1
Affected:
up to 6.1.4
Fixed in:
6.1.5
Disclosed:
Feb 20, 2024

CVE-2024-0365 on NVD →

Fancy Product Designer [fancy-product-designer] < 4.7.0

unknown

[en] The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized access to data and modification of plugin settings due to a missing capability check on multiple AJAX functions in versions up to, and including, 4.6.9. This makes it possible for authenticated attackers with subscriber-level permissions...

Affected:
up to 4.7.0
Fixed in:
4.7.0
Disclosed:
Oct 20, 2023

CVE-2021-4335 on NVD →

Fancy Product Designer [fancy-product-designer] < 4.7.0

unknown

[en] The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a missing capability check on the fpd_update_options function in versions up to, and including, 4.6.9. This makes it possible for authenticated attackers with subscriber-level permissions to modify sit...

Affected:
up to 4.7.0
Fixed in:
4.7.0
Disclosed:
Oct 20, 2023

CVE-2021-4334 on NVD →

Fancy Product Designer <= 4.6.9 - Insufficient Authorization to Arbitrary Options Update via fpd_update_options

high

The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a missing capability check on the fpd_update_options function in versions up to, and including, 4.6.9. This makes it possible for authenticated attackers with subscriber-level permissions to modify site opt...

CVSS:
8.8
Affected:
up to 4.6.9
Fixed in:
4.7.0
Disclosed:
Apr 5, 2023

CVE-2021-4334 on NVD →

Fancy Product Designer <= 4.6.9 - Insufficient Authorization on Mulitple AJAX Actions

medium

The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized access to data and modification of plugin settings due to a missing capability check on multiple AJAX functions in versions up to, and including, 4.6.9. This makes it possible for authenticated attackers with subscriber-level permissions to m...

CVSS:
6.3
Affected:
up to 4.6.9
Fixed in:
4.7.0
Disclosed:
Apr 5, 2023

CVE-2021-4335 on NVD →

Fancy Product Designer [fancy-product-designer] < 4.7.6

unknown

[en] The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import class that makes it possible for attackers to upload malicious files that could be used to gain webshell access to a server in versions up to, and including, 4.7.5.

Affected:
up to 4.7.6
Fixed in:
4.7.6
Disclosed:
Apr 19, 2022

CVE-2021-4096 on NVD →

Fancy Product Designer <= 4.7.5 - Cross-Site Request Forgery to Arbitrary File Upload

high

The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import class that makes it possible for attackers to upload malicious files that could be used to gain webshell access to a server in versions up to, and including, 4.7.5.

CVSS:
8.8
Affected:
up to 4.7.5
Fixed in:
4.7.6
Disclosed:
Apr 14, 2022

CVE-2021-4096 on NVD →

Fancy Product Designer [fancy-product-designer] < 4.7.5

unknown

[en] The Fancy Product Designer WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the ID parameter found in the ~/inc/api/class-view.php file which allows attackers with administrative level permissions to inject arbitrary SQL queries to obtain sensitive information, i...

Affected:
up to 4.7.5
Fixed in:
4.7.5
Disclosed:
Feb 16, 2022

CVE-2021-4134 on NVD →

Fancy Product Designer <= 4.7.4 - Admin+ SQL Injection

high

The Fancy Product Designer WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the ID parameter found in the ~/inc/api/class-view.php file which allows attackers with administrative level permissions to inject arbitrary SQL queries to obtain sensitive information, in ver...

CVSS:
7.2
Affected:
up to 4.7.4
Fixed in:
4.7.5
Disclosed:
Feb 8, 2022

CVE-2021-4134 on NVD →

Fancy Product Designer [fancy-product-designer] < 4.6.9

unknown

[en] The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.

Affected:
up to 4.6.9
Fixed in:
4.6.9
Disclosed:
Jun 21, 2021

CVE-2021-24370 on NVD →

Fancy Product Designer <= 4.6.8 - Unauthenticated Arbitrary File Upload

critical

The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.

CVSS:
9.8
Affected:
up to 4.6.9
Fixed in:
4.6.9
Disclosed:
Jun 1, 2021

CVE-2021-24370 on NVD →

Fancy Product Designer <= 4.5.0 - Stored Cross-Site Scripting

medium

The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in versions up to, and including, 4.5.0 due to insufficient file sanitization. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user...

CVSS:
6.4
Affected:
up to 4.5.0
Fixed in:
4.5.1
Disclosed:
Nov 18, 2020

Fancy Product Designer [fancy-product-designer] < 4.5.1

unknown

The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in versions up to, and including, 4.5.0 due to insufficient file sanitization. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user...

Affected:
up to 4.5.1
Fixed in:
4.5.1
Disclosed:
Nov 18, 2020

Fancy Product Designer [fancy-product-designer] < 4.5.1

unknown

Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability found by Jonathan Gregson in WordPress Fancy Product Designer plugin (versions <= 4.5.0).

Affected:
up to 4.5.1
Fixed in:
4.5.1
Disclosed:
Nov 18, 2020

Fancy Product Designer [fancy-product-designer] < 4.5.1

unknown

Fancy Product Designer for WooCommerce before version 4.5.1 permits the upload of unsanitized SVG files by unauthenticated users. SVG files can contain JavaScript which will be executed by the browser if the malicious SVG is accessed directly. This JavaScript will run in the context of the affected domain and logged in...

Affected:
up to 4.5.1
Fixed in:
4.5.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database