The Fancy Product Designer WordPress plugin before 6.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against unauthenticated and admin-level users
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 08 May 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Radykal
Radykal fancy Product Designer |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:radykal:fancy_product_designer:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Radykal
Radykal fancy Product Designer |
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-01T18:18:19.000Z
Reserved: 2024-01-25T19:59:26.093Z
Link: CVE-2024-0905
Updated: 2024-08-01T18:18:19.000Z
Status : Analyzed
Published: 2024-04-26T05:15:49.907
Modified: 2025-05-08T19:14:27.803
Link: CVE-2024-0905
No data.
OpenCVE Enrichment
No data.
Weaknesses