<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Web to Print Product Designer for WooCommerce (&lt;= 2.8.5) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/web-to-print-product-designer-for-woocommerce--2.8.5/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 18 Sep 2026 10:05:03 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/web-to-print-product-designer-for-woocommerce--2.8.5/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Directory Traversal in Printcart Web to Print Product Designer for WooCommerce</title><link>https://feed.craftedsignal.io/briefs/2026-09-printcart-traversal/</link><pubDate>Fri, 18 Sep 2026 10:05:03 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-printcart-traversal/</guid><description>The Printcart Web to Print Product Designer for WooCommerce plugin contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary server files.</description><content:encoded>&lt;p>The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to a directory traversal flaw in versions 2.8.5 and earlier. The vulnerability exists within the 'mockups' parameter, allowing unauthenticated attackers to access and read sensitive files from the underlying server filesystem.&lt;/p>
&lt;p>The exploitation process is simplified by the plugin's insecure implementation of nonce validation. Unauthenticated users can retrieve a valid 'nbdesigner-get-data' nonce from the 'nbd_check_use_logged_in' AJAX endpoint. Furthermore, if the 'NBDESIGNER_ENABLE_NONCE' constant is explicitly set to false, the security gate is removed entirely, allowing direct exploitation of the traversal vulnerability. This flaw poses a significant risk to affected WordPress installations, as it facilitates the exfiltration of sensitive configuration files, including wp-config.php, which often contains database credentials.&lt;/p>
</content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>