PatchSiren

Printcart CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Printcart CVE published 2026-07-27

CVE-2025-15662

The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 is vulnerable to unauthenticated local file disclosure and server-side request forgery (SSRF) attacks. An attacker can exploit this vulnerability to read arbitrary local files, including configuration files containing sensitive information such as database credentials and secret keys, and make server-side requests to [truncated]

CRITICAL printcart CVE published 2026-07-03

CVE-2026-9725

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2. This vulnerability exists due to insufficient path validation in the store_design_data() function, which constructs a filesystem path from the user-supplied 'nbd_item_key' POST parameter. The parameter is sanitized only with sanitize_text_field( [truncated]