Skip to content
Threat Feed
high advisory

Directory Traversal in Printcart Web to Print Product Designer for WooCommerce

The Printcart Web to Print Product Designer for WooCommerce plugin contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary server files.

CVE search metadata

CVE search record: CVE-2026-14323. Severity: high. CVSS: 7.5. KEV: no. Product: Web to Print Product Designer for WooCommerce (<= 2.8.5). Brief: Directory Traversal in Printcart Web to Print Product Designer for WooCommerce. Brief link: https://feed.craftedsignal.io/briefs/2026-09-printcart-traversal/

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to a directory traversal flaw in versions 2.8.5 and earlier. The vulnerability exists within the 'mockups' parameter, allowing unauthenticated attackers to access and read sensitive files from the underlying server filesystem.

The exploitation process is simplified by the plugin's insecure implementation of nonce validation. Unauthenticated users can retrieve a valid 'nbdesigner-get-data' nonce from the 'nbd_check_use_logged_in' AJAX endpoint. Furthermore, if the 'NBDESIGNER_ENABLE_NONCE' constant is explicitly set to false, the security gate is removed entirely, allowing direct exploitation of the traversal vulnerability. This flaw poses a significant risk to affected WordPress installations, as it facilitates the exfiltration of sensitive configuration files, including wp-config.php, which often contains database credentials.


Immediate actions

Patch Printcart Web to Print Product Designer for WooCommerce to the latest version.

IT Operations 24h

Mitigations

Deploy WAF rules to filter directory traversal patterns in the 'mockups' parameter.

immediate SOC

CVE-2026-14323

Detection coverage 1

Detects CVE-2026-14323 Exploitation - Directory Traversal in Printcart Plugin

high

Detects exploitation attempts against CVE-2026-14323 by identifying directory traversal sequences in the mockups parameter of WordPress plugin requests.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →