Impact
The Product Designer App plugin for WordPress contains a directory traversal flaw in its 'pdapp-render-design' endpoint, where the 'svg' parameter can be manipulated to read any file on the server. This vulnerability allows an attacker to obtain the contents of arbitrary files, exposing sensitive data or credentials without needing authentication. The flaw corresponds to CWE‑22, a classic path traversal weakness.
Affected Systems
All installations of the Product Designer App plugin up to and including version 1.1.3 are affected. Any WordPress site that includes the [pdapp-studio-page] shortcode and exposes the related AJAX endpoint is at risk, regardless of the site’s authentication state.
Risk and Exploitability
The CVSS v3.1 score of 7.5 classifies this as a high‑severity flaw. Because the nonce and token used for access control are emitted publicly as JavaScript globals, the authentication gate is effectively bypassed, making exploitation straightforward for anonymous visitors through crafted HTTP requests. The EPSS score is not available, and the vulnerability is not yet listed in the CISA KEV catalog; however, its public exposure and the absence of a practical defense imply a non‑negligible risk of exploitation.
OpenCVE Enrichment