Unauthenticated Directory Traversal in WordPress Product Designer App Plugin
The Product Designer App plugin for WordPress up to version 1.1.3 is vulnerable to directory traversal allowing unauthenticated file read due to insecurely implemented authentication using publicly exposed tokens.
CVE search metadata
CVE search record: CVE-2026-75098. Severity: high. CVSS: 7.5. KEV: no. Product: Product Designer App (<= 1.1.3). Brief: Unauthenticated Directory Traversal in WordPress Product Designer App Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-09-product-designer-app-traversal/
The Product Designer App plugin for WordPress, in all versions up to and including 1.1.3, contains a critical directory traversal vulnerability. Attackers can leverage this flaw to read arbitrary files from the underlying server filesystem. The plugin attempts to gate access to the vulnerable endpoint using a nonce and token mechanism; however, these values are rendered as global JavaScript variables on any page that utilizes the [pdapp-studio-page] shortcode. Because these credentials are publicly accessible to any anonymous visitor, the security control is effectively bypassed. This allows unauthenticated remote attackers to perform unauthorized file reads, potentially accessing sensitive configuration files, credentials, or system data. Defenders should prioritize updating the plugin to the latest patched version or removing the plugin if it cannot be immediately updated.
Attack Chain
- Attacker identifies a WordPress site running the Product Designer App plugin.
- Attacker visits any page on the target site that renders the [pdapp-studio-page] shortcode.
- Attacker parses the page source to extract the nonce and token values exposed as JavaScript global variables.
- Attacker crafts a malicious HTTP request targeting the plugin endpoint, incorporating the harvested nonce and token for authentication.
- Attacker injects directory traversal sequences (e.g., ../) into the 'svg' parameter of the request.
- The plugin processes the input, failing to validate the path traversal, and returns the requested system file content in the HTTP response.
Impact
Successful exploitation allows unauthenticated attackers to read arbitrary files on the web server. This can lead to the exposure of database credentials in wp-config.php, sensitive application environment variables, or private source code, facilitating full site compromise or lateral movement within the hosting environment.
Recommendation
- Immediately update the Product Designer App plugin to a version later than 1.1.3 once a vendor patch is released.
- If no patch is available, disable or uninstall the plugin to eliminate the exposure of the vulnerable [pdapp-studio-page] shortcode.
- Implement web application firewall (WAF) rules to detect and block requests to the vulnerable plugin endpoint containing directory traversal sequences (e.g., ../, ../) in the 'svg' parameter.
- Audit access logs for high-frequency requests originating from single IPs targeting plugin-specific paths to identify potential automated scanning or exploitation attempts.
Immediate actions
Block requests with directory traversal patterns targeting the plugin
Mitigations
Update Product Designer App to patched version when available
CVE-2026-75098
Detection coverage 1
Detect CVE-2026-75098 Exploitation Attempt - Path Traversal in Product Designer App
highDetects HTTP requests targeting the Product Designer App with directory traversal sequences in the svg parameter
Detection queries are available on the platform. Get full rules →