Impact
The plugin contains a directory traversal flaw in the 'mockups' parameter that allows an attacker to request arbitrary files from the server. The vulnerability also leverages a public AJAX endpoint that issues a nonce without authentication, or can be bypassed entirely when the NBDESIGNER_ENABLE_NONCE constant is disabled. When exploitation succeeds, the attacker can read sensitive configuration files or other data that should not be exposed to the web.
Affected Systems
Sites running Printcart Store – Web to Print Product Designer for WooCommerce WordPress plugin version 2.8.5 or earlier are affected. The flaw resides in the plugin’s class.nbdesigner.php and class.resource.php code pathways that handle the 'mockups' request.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, but the EPSS score of < 1% shows that, to date, the exploitation likelihood is low. The vulnerability is not listed in the CISA KEV catalog, yet the ability to read arbitrary files poses a serious confidentiality risk. An unauthenticated attacker can trigger the flaw simply by sending an HTTP request to the vulnerable AJAX endpoint, providing the requested file path in the parameters. The presence of an easily obtainable nonce, and the option to bypass nonce checks entirely when a certain constant is disabled, reduces the barrier to exploitation.
OpenCVE Enrichment