{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/product-designer-app--1.1.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:product_designer_app:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-75098"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Product Designer App (\u003c= 1.1.3)"],"_cs_severities":["high"],"_cs_tags":["wordpress","vulnerability","web-application","file-read","directory-traversal"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Product Designer App plugin for WordPress, in all versions up to and including 1.1.3, contains a critical directory traversal vulnerability. Attackers can leverage this flaw to read arbitrary files from the underlying server filesystem. The plugin attempts to gate access to the vulnerable endpoint using a nonce and token mechanism; however, these values are rendered as global JavaScript variables on any page that utilizes the [pdapp-studio-page] shortcode. Because these credentials are publicly accessible to any anonymous visitor, the security control is effectively bypassed. This allows unauthenticated remote attackers to perform unauthorized file reads, potentially accessing sensitive configuration files, credentials, or system data. Defenders should prioritize updating the plugin to the latest patched version or removing the plugin if it cannot be immediately updated.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site running the Product Designer App plugin.\u003c/li\u003e\n\u003cli\u003eAttacker visits any page on the target site that renders the [pdapp-studio-page] shortcode.\u003c/li\u003e\n\u003cli\u003eAttacker parses the page source to extract the nonce and token values exposed as JavaScript global variables.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP request targeting the plugin endpoint, incorporating the harvested nonce and token for authentication.\u003c/li\u003e\n\u003cli\u003eAttacker injects directory traversal sequences (e.g., ../) into the 'svg' parameter of the request.\u003c/li\u003e\n\u003cli\u003eThe plugin processes the input, failing to validate the path traversal, and returns the requested system file content in the HTTP response.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to read arbitrary files on the web server. This can lead to the exposure of database credentials in wp-config.php, sensitive application environment variables, or private source code, facilitating full site compromise or lateral movement within the hosting environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Product Designer App plugin to a version later than 1.1.3 once a vendor patch is released.\u003c/li\u003e\n\u003cli\u003eIf no patch is available, disable or uninstall the plugin to eliminate the exposure of the vulnerable [pdapp-studio-page] shortcode.\u003c/li\u003e\n\u003cli\u003eImplement web application firewall (WAF) rules to detect and block requests to the vulnerable plugin endpoint containing directory traversal sequences (e.g., ../, ../) in the 'svg' parameter.\u003c/li\u003e\n\u003cli\u003eAudit access logs for high-frequency requests originating from single IPs targeting plugin-specific paths to identify potential automated scanning or exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-30T10:34:19Z","date_published":"2026-09-30T10:34:19Z","id":"https://feed.craftedsignal.io/briefs/2026-09-product-designer-app-traversal/","summary":"The Product Designer App plugin for WordPress up to version 1.1.3 is vulnerable to directory traversal allowing unauthenticated file read due to insecurely implemented authentication using publicly exposed tokens.","title":"Unauthenticated Directory Traversal in WordPress Product Designer App Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-product-designer-app-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Product Designer App (\u003c= 1.1.3)","version":"https://jsonfeed.org/version/1.1"}