The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 is vulnerable to unauthenticated local file disclosure and server-side request forgery (SSRF) attacks. An attacker can exploit this vulnerability to read arbitrary local files, including configuration files containing sensitive information such as database credentials and secret keys, and make server-side requests to [truncated]
The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2. This vulnerability exists due to insufficient path validation in the store_design_data() function, which constructs a filesystem path from the user-supplied 'nbd_item_key' POST parameter. The parameter is sanitized only with sanitize_text_field( [truncated]