Skip to main content

Vendor/product archive

radykal / fancy_product_designer CVEs

Beta · best-effort

9 CVEs tagged to radykal / fancy_product_designer1 Critical, 3 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2024-0904

Published May 6, 2024

The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0905

Published Apr 26, 2024

The Fancy Product Designer WordPress plugin before 6.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scriptin…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0902

Published Apr 15, 2024

The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0365

Published Mar 18, 2024

The Fancy Product Designer WordPress plugin before 6.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitab…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-4334

Published Oct 20, 2023

The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a missing capability check on the fpd_update_options function in…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-4335

Published Oct 20, 2023

The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized access to data and modification of plugin settings due to a missing capability check on multiple AJAX…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-4096

Published Apr 19, 2022

The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import class that makes it possible for attackers to upload malicious…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-4134

Published Feb 16, 2022

The Fancy Product Designer WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the ID parameter found in the ~/inc/api/class-view.…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-24370

Published Jun 21, 2021

The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1