{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aprintcartweb_to_print_product_designer_for_woocommerce/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:printcart:web_to_print_product_designer_for_woocommerce:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-14323"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Web to Print Product Designer for WooCommerce (\u003c= 2.8.5)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Printcart"],"content_html":"\u003cp\u003eThe Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to a directory traversal flaw in versions 2.8.5 and earlier. The vulnerability exists within the 'mockups' parameter, allowing unauthenticated attackers to access and read sensitive files from the underlying server filesystem.\u003c/p\u003e\n\u003cp\u003eThe exploitation process is simplified by the plugin's insecure implementation of nonce validation. Unauthenticated users can retrieve a valid 'nbdesigner-get-data' nonce from the 'nbd_check_use_logged_in' AJAX endpoint. Furthermore, if the 'NBDESIGNER_ENABLE_NONCE' constant is explicitly set to false, the security gate is removed entirely, allowing direct exploitation of the traversal vulnerability. This flaw poses a significant risk to affected WordPress installations, as it facilitates the exfiltration of sensitive configuration files, including wp-config.php, which often contains database credentials.\u003c/p\u003e\n","date_modified":"2026-09-18T10:05:03Z","date_published":"2026-09-18T10:05:03Z","id":"https://feed.craftedsignal.io/briefs/2026-09-printcart-traversal/","summary":"The Printcart Web to Print Product Designer for WooCommerce plugin contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary server files.","title":"Directory Traversal in Printcart Web to Print Product Designer for WooCommerce","url":"https://feed.craftedsignal.io/briefs/2026-09-printcart-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:printcart:web_to_print_product_designer_for_woocommerce:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}