plugin

Product Designer Vulnerabilities

7 known security issues reported for the Product Designer WordPress plugin. Most recent disclosed Nov 21, 2024.

1 critical 2 medium

Running Product Designer on your site? Check whether your installed version is affected.

Scan your site free

Product Designer [product-designer] < 1.0.37

unknown

[en] The Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbi...

Affected:
up to 1.0.37
Fixed in:
1.0.37
Disclosed:
Nov 21, 2024

CVE-2024-9111 on NVD →

Product Designer <= 1.0.36 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

medium

The Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.36 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary...

CVSS:
6.4
Affected:
up to 1.0.36
Fixed in:
1.0.37
Disclosed:
Nov 20, 2024

CVE-2024-9111 on NVD →

Product Designer [product-designer] < 1.0.34

unknown

[en] Missing Authorization vulnerability in PickPlugins Product Designer allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Product Designer: from n/a through 1.0.33.

Affected:
up to 1.0.34
Fixed in:
1.0.34
Disclosed:
Nov 1, 2024

CVE-2024-38726 on NVD →

Product Designer [product-designer] < 1.0.34

unknown

[en] The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the product_designer_ajax_delete_attach_id() function in all versions up to, and including, 1.0.33. This makes it possible for unauthenticated attackers to delete arbitrary attachments.

Affected:
up to 1.0.34
Fixed in:
1.0.34
Disclosed:
Jul 9, 2024

CVE-2024-3608 on NVD →

Product Designer <= 1.0.33 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion

medium

The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the product_designer_ajax_delete_attach_id() function in all versions up to, and including, 1.0.33. This makes it possible for unauthenticated attackers to delete arbitrary attachments. CVE-2024-387...

CVSS:
5.3
Affected:
up to 1.0.33
Fixed in:
1.0.34
Disclosed:
Jul 8, 2024

CVE-2024-3608 on NVD →

Product Designer [product-designer] < 1.0.33

unknown

[en] Deserialization of Untrusted Data vulnerability in PickPlugins Product Designer.This issue affects Product Designer: from n/a through 1.0.32.

Affected:
up to 1.0.33
Fixed in:
1.0.33
Disclosed:
Apr 7, 2024

CVE-2024-31277 on NVD →

Product Designer <= 1.0.32 - Unauthenticated PHP Object Injection

critical

The Product Designer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.32 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is pres...

CVSS:
9.8
Affected:
up to 1.0.32
Fixed in:
1.0.33
Disclosed:
Apr 5, 2024

CVE-2024-31277 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database