CVE-2026-75098
Received Received - Intake

Directory Traversal in Product Designer App WordPress Plugin

Vulnerability report for CVE-2026-75098, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Wordfence

Description

The Product Designer App plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.3 via the 'svg' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The endpoint's only authentication gate relies on a nonce and token that are both publicly emitted as JavaScript globals on any page rendering the [pdapp-studio-page] shortcode, making them freely obtainable by anonymous visitors.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
product_designer_app plugin to 1.1.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Directory Traversal issue in the Product Designer App plugin for WordPress, affecting versions up to 1.1.3. It allows unauthenticated attackers to read arbitrary files on the server by exploiting the 'svg' parameter. The plugin's authentication relies on a nonce and token exposed as JavaScript globals on pages with the [pdapp-studio-page] shortcode, making them easily accessible to anonymous users.

Detection Guidance

Check if the Product Designer App plugin version 1.1.3 or lower is installed in your WordPress site. Look for unauthorized file access attempts or unusual requests targeting the vulnerable 'svg' parameter endpoint.

Impact Analysis

Attackers could access sensitive files on your server, such as configuration files, user data, or other confidential information. This could lead to data breaches, unauthorized access to system files, or further exploitation of your WordPress environment.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, or other regulations by exposing sensitive personal or health data. Unauthorized file access may violate data protection requirements, resulting in legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Update the Product Designer App plugin to the latest version if available. If no update exists, consider disabling or removing the plugin immediately. Review server logs for signs of exploitation and restrict access to sensitive files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75098. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart