{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/fancy-product-designer--6.5.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:fancy_product_designer:fancy_product_designer:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-84279"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Fancy Product Designer (\u003c= 6.5.2)"],"_cs_severities":["high"],"_cs_tags":["xss","web-vulnerability","wordpress"],"_cs_type":"advisory","_cs_vendors":["Fancy Product Designer"],"content_html":"\u003cp\u003eThe Fancy Product Designer plugin for WordPress is affected by a stored cross-site scripting (XSS) vulnerability, identified as CVE-2026-84279. The flaw resides in the 'output_format' parameter and affects all versions up to and including 6.5.2. The vulnerability stems from inadequate input sanitization and output escaping within the plugin's code. To exploit this, the 'Pro Export/Genius' feature must be enabled, as the vulnerable 'fpd_pr_export' AJAX action is only registered when this feature is active. An unauthenticated attacker can leverage this flaw to inject arbitrary web scripts into pages. These scripts execute in the context of a victim's browser whenever they access an affected page, potentially leading to unauthorized actions, session hijacking, or credential theft. This vulnerability represents a significant risk to WordPress sites utilizing the affected plugin and feature configuration.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the browsers of users viewing the injected content. This could result in unauthorized administrative actions, the theft of session cookies, redirection to malicious domains, or the exfiltration of sensitive user data. The vulnerability impacts all WordPress sites running the vulnerable plugin versions with the specified feature enabled.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Fancy Product Designer plugin to the latest version beyond 6.5.2 to remediate CVE-2026-84279.\u003c/li\u003e\n\u003cli\u003eDisable the 'Pro Export/Genius' feature if it is not strictly required for site functionality until an update can be applied.\u003c/li\u003e\n\u003cli\u003eMonitor web application firewall (WAF) logs for POST requests directed at the 'fpd_pr_export' AJAX action that contain suspicious script tags or JavaScript event handlers in the 'output_format' parameter.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-25T08:54:35Z","date_published":"2026-09-25T08:54:35Z","id":"https://feed.craftedsignal.io/briefs/2026-09-fancy-product-designer-xss/","summary":"An unauthenticated stored cross-site scripting vulnerability in the Fancy Product Designer WordPress plugin allows attackers to inject malicious scripts via the output_format parameter.","title":"Stored XSS in Fancy Product Designer WordPress Plugin (CVE-2026-84279)","url":"https://feed.craftedsignal.io/briefs/2026-09-fancy-product-designer-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Fancy Product Designer (\u003c= 6.5.2)","version":"https://jsonfeed.org/version/1.1"}