WordPress Fancy Product Designer plugin before 4.6.9 is susceptible to an arbitrary file upload. An attacker can upload malicious files and execute code on the server, modify data, and/or gain full control over a compromised system without authentication.
id: CVE-2021-24370
info:
name: WordPress Fancy Product Designer <4.6.9 - Arbitrary File Upload
...