CPE
The Product Designer App plugin for WordPress up to version 1.1.3 is vulnerable to directory traversal allowing unauthenticated file read due to insecurely implemented authentication using publicly exposed tokens.