plugin

Riaxe Product Customizer Vulnerabilities

4 known security issues reported for the Riaxe Product Customizer WordPress plugin. Most recent disclosed Apr 15, 2026.

1 critical 1 high 2 medium

Running Riaxe Product Customizer on your site? Check whether your installed version is affected.

Scan your site free

Riaxe Product Customizer <= 2.1.2 - Unauthenticated SQL Injection via 'options' Parameter Keys in product_data

high

The Riaxe Product Customizer plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter keys within 'product_data' of the /wp-json/InkXEProductDesignerLite/add-item-to-cart REST API endpoint in all versions up to, and including, 2.1.2. This is due to insufficient escaping on the user-supplied param...

CVSS:
7.5
Affected:
up to 2.1.2
Fix:
No patched version reported
Disclosed:
Apr 15, 2026

CVE-2026-3599 on NVD →

Riaxe Product Customizer <= 2.1.2 - Unauthenticated Arbitrary User Deletion via 'user_id' Parameter

medium

The Riaxe Product Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.2. This is due to the plugin registering a REST API route at POST /wp-json/InkXEProductDesignerLite/customer/delete_customer without a permission_callback, causing WordPress to default to al...

CVSS:
5.3
Affected:
up to 2.1.2
Fix:
No patched version reported
Disclosed:
Apr 15, 2026

CVE-2026-3595 on NVD →

Riaxe Product Customizer <= 2.1.2 - Missing Authorization to Unauthenticated Arbitrary Options Update to Privilege Escalation via 'install-imprint' AJAX Action

critical

The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.2. The plugin registers an unauthenticated AJAX action ('wp_ajax_nopriv_install-imprint') that maps to the ink_pd_add_option() function. This function reads 'option' and 'opt_value' from $_P...

CVSS:
9.8
Affected:
up to 2.1.2
Fix:
No patched version reported
Disclosed:
Apr 15, 2026

CVE-2026-3596 on NVD →

Riaxe Product Customizer <= 2.4 - Unauthenticated Sensitive Information Disclosure via '/orders' REST API Endpoint

medium

The Riaxe Product Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4 via the '/wp-json/InkXEProductDesignerLite/orders' REST API endpoint. The endpoint is registered with 'permission_callback' set to '__return_true', meaning no authentication or aut...

CVSS:
5.3
Affected:
up to 2.4
Fix:
No patched version reported
Disclosed:
Apr 7, 2026

CVE-2026-3594 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database