Sceawere

Vulnerability Detail

CVE-2026-75098UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Product Designer Directory Traversal

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
productdesignerapp
Product
Product Designer App
Attack Type
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Product Designer App plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.3 via the 'svg' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The endpoint's only authentication gate relies on a nonce and token that are both publicly emitted as JavaScript globals on any page rendering the [pdapp-studio-page] shortcode, making them freely obtainable by anonymous visitors.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-30T09:17:16.320Z",
  "pubdate": "2026-09-30T09:17:16.320Z",
  "executiveSummary": "The Product Designer App plugin for WordPress, up to and including version 1.1.3, is affected by a critical security vulnerability classified as arbitrary file read via directory traversal. An unauthenticated remote attacker can exploit this weakness to access sensitive files stored on the hosting server's filesystem, such as configuration files containing database credentials, system logs, or environment variables. This capability significantly compromises the confidentiality of the affected host and can serve as a stepping stone for further compromise, including remote code execution or full site takeover.\nAlthough the vulnerability resides within an endpoint protected by an authentication gate utilizing a cryptographic nonce and a session token, this defensive control is effectively bypassed. The required nonce and token parameters are publicly exposed as JavaScript global variables on any page rendering the [pdapp-studio-page] shortcode. Consequently, any anonymous visitor can easily retrieve these credentials from the front-end page source and use them to authorize malicious requests. This removes any operational barrier to exploitation, making the vulnerability highly exploitable with severe risk implications for organizations running the vulnerable plugin versions.",
  "technicalDetails": "The core of the vulnerability lies in the improper sanitization and validation of user-controlled input within the Product Designer App WordPress plugin, specifically through the 'svg' parameter. The application fails to adequately restrict path inputs, allowing directory traversal sequences (such as '../../') to be processed. Consequently, an attacker can manipulate the 'svg' parameter to traverse the directory structure of the local filesystem and read arbitrary files that the web server process has permissions to access.\nUnder normal conditions, access to the vulnerable endpoint is restricted using a dual-token mechanism consisting of a WordPress security nonce and a custom session token. This authentication gate is intended to verify that the request originates from a legitimate session. However, the design of the plugin undermines this security boundary. When a page rendering the [pdapp-studio-page] shortcode is loaded, the application outputs the active nonce and token as global variables in the JavaScript context of the rendered document.\nBecause these tokens are visible in the client-side DOM, an unauthenticated attacker can orchestrate a multi-stage attack flow: 1. The attacker performs an initial HTTP GET request to any public-facing page containing the [pdapp-studio-page] shortcode. 2. The attacker parses the HTML response to extract the exposed nonce and token values from the JavaScript global variables. 3. Armed with these valid authorization parameters, the attacker constructs a crafted HTTP request targeted at the vulnerable endpoint handling the 'svg' parameter. 4. Within this request, the attacker populates the 'svg' parameter with directory traversal sequences pointing to a sensitive file, such as '/etc/passwd' or the WordPress configuration file 'wp-config.php' (e.g., '../../../../wp-config.php'). 5. The server-side script processes the request, resolves the traversed path relative to the expected directory, and returns the contents of the target file in the HTTP response.\nSince the web server user (such as www-data) typically requires read access to critical application configuration files, the post-exploitation impact is severe. An attacker who successfully extracts 'wp-config.php' gains direct access to database credentials, database host details, and unique authentication keys/salts, which can be leveraged to compromise the database or forge session cookies to escalate privileges to the administrator level."
}
CVE-2026-75098: Product Designer Directory Traversal (HIGH Severity, CVSS: 7.5) | Sceawere