Impact
The Printcart Web to Print Product Designer for WooCommerce plugin, before version 2.5.3, fails to validate user‑supplied URLs before fetching them and does not enforce an authorization check. This flaw permits any web user to read any local file accessible to the web server, including configuration files that may contain database credentials and secret keys, and to trigger server‑side requests to internal resources, resulting in a server‑side request forgery (SSRF) opportunity. Based on the description, it is inferred that files such as wp‑config.php could be read by malicious actors.
Affected Systems
WordPress sites that have the Printcart Web to Print Product Designer for WooCommerce plugin installed with a version earlier than 2.5.3 are impacted. The plugin is typically used on e‑commerce stores that offer customizable product design, as inferred from its purpose of allowing product designers within WooCommerce. The vulnerability is accessible to anyone who can reach the WordPress site via HTTP or HTTPS, regardless of authentication status.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity vulnerability. The EPSS score of <1% suggests that exploitation is unlikely at this time, yet the lack of an authentication requirement and the presence of both an arbitrary file read and SSRF flaw mean that exploitation is straightforward for an attacker who can send a crafted HTTP request. The vulnerability is not listed in CISA KEV. An attacker could therefore read sensitive configuration files or force the server to contact internal services, potentially exposing credentials or enabling further compromise of the network.
OpenCVE Enrichment