Impact
The Fancy Product Designer WordPress plugin is vulnerable to stored cross‑site scripting due to unsanitized productTitle data in order item meta. An unauthenticated attacker can inject arbitrary JavaScript that runs whenever a user views an order in the admin interface. This can lead to defacement, cookie theft, session hijacking, or other malicious activities. The flaw is a CWE‑79 unsafe return of content to the browser.
Affected Systems
The vulnerability affects all installations of the Fancy Product Designer plugin by radykal that are version 6.5.2 or earlier. Administrators running these versions on WordPress sites should evaluate their installation.
Risk and Exploitability
The CVSS score of 7.2 reflects the high potential for exploitation and loss of confidentiality, integrity, or availability. Although no EPSS score is available, the lack of a nonce or capability check in the fpd_save_order AJAX endpoint enables attackers to submit malicious payloads from any network. The vulnerability is not listed in the CISA KEV catalog, but the attack path is simple and not restricted to privileged users. Administrators should treat the exposure as high risk and prioritize remediation.
OpenCVE Enrichment