Product Designer [product-designer] < 1.0.37
unknown
[en] The Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbi...
- Affected:
- up to 1.0.37
- Fixed in:
- 1.0.37
- Disclosed:
- Nov 21, 2024
CVE-2024-9111 on NVD →
Product Designer <= 1.0.36 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
medium
The Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.36 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary...
- CVSS:
- 6.4
- Affected:
- up to 1.0.36
- Fixed in:
- 1.0.37
- Disclosed:
- Nov 20, 2024
CVE-2024-9111 on NVD →
Product Designer [product-designer] < 1.0.34
unknown
[en] Missing Authorization vulnerability in PickPlugins Product Designer allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Product Designer: from n/a through 1.0.33.
- Affected:
- up to 1.0.34
- Fixed in:
- 1.0.34
- Disclosed:
- Nov 1, 2024
CVE-2024-38726 on NVD →
Product Designer [product-designer] < 1.0.34
unknown
[en] The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the product_designer_ajax_delete_attach_id() function in all versions up to, and including, 1.0.33. This makes it possible for unauthenticated attackers to delete arbitrary attachments.
- Affected:
- up to 1.0.34
- Fixed in:
- 1.0.34
- Disclosed:
- Jul 9, 2024
CVE-2024-3608 on NVD →
Product Designer <= 1.0.33 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion
medium
The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the product_designer_ajax_delete_attach_id() function in all versions up to, and including, 1.0.33. This makes it possible for unauthenticated attackers to delete arbitrary attachments. CVE-2024-387...
- CVSS:
- 5.3
- Affected:
- up to 1.0.33
- Fixed in:
- 1.0.34
- Disclosed:
- Jul 8, 2024
CVE-2024-3608 on NVD →
Product Designer [product-designer] < 1.0.33
unknown
[en] Deserialization of Untrusted Data vulnerability in PickPlugins Product Designer.This issue affects Product Designer: from n/a through 1.0.32.
- Affected:
- up to 1.0.33
- Fixed in:
- 1.0.33
- Disclosed:
- Apr 7, 2024
CVE-2024-31277 on NVD →
Product Designer <= 1.0.32 - Unauthenticated PHP Object Injection
critical
The Product Designer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.32 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is pres...
- CVSS:
- 9.8
- Affected:
- up to 1.0.32
- Fixed in:
- 1.0.33
- Disclosed:
- Apr 5, 2024
CVE-2024-31277 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database