Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-75098— Product Designer App <= 1.1.3 - Unauthenticated Arbitrary File Read via 'svg' Parameter in pdapp-render-design

Quick assessment

Affected
productdesignerapp Product Designer App
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 的 Product Designer App 插件在包括 1.1.3 在内的所有版本中均存在目录遍历(Directory Traversal)漏洞,该漏洞可通过 参数触发。这使得未经身份验证的攻击者能够读取服务器上的任意文件内容,而这些文件可能包含敏感信息。该端点唯一的身份验证机制依赖于一个 nonce(一次性令牌)和一个 token,而这两个值均作为 JavaScript 全局变量公开输出在渲染了 短代码的任何页面上,因此匿名访客可以轻易获取它们。

CVSS 7.5 · High

Possible ATT&CK Techniques 1 AI

T1083 · File and Directory Discovery
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-75098

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Product Designer App <= 1.1.3 - Unauthenticated Arbitrary File Read via 'svg' Parameter in pdapp-render-design
Source: CVE Program / CVE List V5
Vulnerability Description
The Product Designer App plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.3 via the 'svg' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The endpoint's only authentication gate relies on a nonce and token that are both publicly emitted as JavaScript globals on any page rendering the [pdapp-studio-page] shortcode, making them freely obtainable by anonymous visitors.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
productdesignerapp Product Designer App 0 ~ 1.1.3 -

II. Public POCs for CVE-2026-75098

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-75098

请登录查看更多情报信息。

Other References for CVE-2026-75098 (1)

Other References for CVE-2026-75098 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-75098

No comments yet


Leave a comment