← WordPress Vulnerabilities
WordPress security by component

Fancy Product Designer

Fancy Product Designer is a WordPress component with 15 published CVE records in this archive. The latest tracked vulnerability was published Jan 16, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: fancy-product-designer

CVE-2025-15526: Fancy Product Designer: A security weakness

Fancy Product Designer is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedJan 16, 2026
Safe version guidanceSee mitigation notes
Safe version
Jan 16, 2026 CVE-2025-15526
Fancy Product Designer: A security weakness
Fancy Product Designer is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Dec 16, 2025 CVE-2025-13231
Fancy Product Designer: Server-side request forgery
Fancy Product Designer is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE6.5
NVDPending
Dec 16, 2025 CVE-2025-13439
Fancy Product Designer: Code execution
Fancy Product Designer is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE5.9
NVDPending
Dec 12, 2025 CVE-2025-12570
Fancy Product Designer: Cross-site scripting
Fancy Product Designer is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVDPending
Jan 21, 2025 CVE-2024-51919
Fancy Product Designer: Dangerous file upload
Fancy Product Designer is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE9.0
NVDPending
Jan 21, 2025 CVE-2024-51818
Fancy Product Designer: SQL injection
Fancy Product Designer is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.3
NVDPending
May 06, 2024 CVE-2024-0904
Fancy Product Designer: Cross-site scripting
Fancy Product Designer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Apr 26, 2024 CVE-2024-0905
Fancy Product Designer: Cross-site scripting
Fancy Product Designer is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.3
NVDPending
Apr 15, 2024 CVE-2024-0902
Fancy Product Designer: Cross-site scripting
Fancy Product Designer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.3
NVD4.8
Mar 18, 2024 CVE-2024-0365
Fancy Product Designer: SQL injection
Fancy Product Designer is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE6.5
NVDPending
Oct 20, 2023 CVE-2021-4334
Fancy Product Designer: Privilege escalation or authentication bypass
Fancy Product Designer is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVD8.8
Oct 20, 2023 CVE-2021-4335
Fancy Product Designer: A security weakness
Fancy Product Designer is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.3
NVD6.3
Apr 19, 2022 CVE-2021-4096
Fancy Product Designer: Cross-site request forgery
Fancy Product Designer is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVD8.8
Feb 16, 2022 CVE-2021-4134
Fancy Product Designer: SQL injection
Fancy Product Designer is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVD4.9
Jun 21, 2021 CVE-2021-24370
Fancy Product Designer: Code execution
Fancy Product Designer is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVD9.8