WordPress security by component
Fancy Product Designer
Plugin description
Fancy Product Designer allows customers to customize products with text, images, colors, and design elements before placing orders.
Fancy Product Designer (fancy-product-designer) is a WordPress plugin with 15 published CVE records in this archive. The latest tracked vulnerability was published Jan 16, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
fancy-product-designerLatest vulnerability
CVE-2025-15526: Fancy Product Designer: A security weakness
Fancy Product Designer is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
| Safe version |
|
||
|---|---|---|---|
| Jan 16, 2026 |
CVE-2025-15526
Fancy Product Designer: A security weakness
Fancy Product Designer is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Dec 16, 2025 |
CVE-2025-13231
Fancy Product Designer: Server-side request forgery
Fancy Product Designer is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Dec 16, 2025 |
CVE-2025-13439
Fancy Product Designer: Code execution
Fancy Product Designer is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Dec 12, 2025 |
CVE-2025-12570
Fancy Product Designer: Cross-site scripting
Fancy Product Designer is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Jan 21, 2025 |
CVE-2024-51919
Fancy Product Designer: Dangerous file upload
Fancy Product Designer is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE9.0
NVDPending
|
| Jan 21, 2025 |
CVE-2024-51818
Fancy Product Designer: SQL injection
Fancy Product Designer is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.3
NVDPending
|
| May 06, 2024 |
CVE-2024-0904
Fancy Product Designer: Cross-site scripting
Fancy Product Designer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Apr 26, 2024 |
CVE-2024-0905
Fancy Product Designer: Cross-site scripting
Fancy Product Designer is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.3
NVDPending
|
| Apr 15, 2024 |
CVE-2024-0902
Fancy Product Designer: Cross-site scripting
Fancy Product Designer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.3
NVD4.8
|
| Mar 18, 2024 |
CVE-2024-0365
Fancy Product Designer: SQL injection
Fancy Product Designer is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Oct 20, 2023 |
CVE-2021-4334
Fancy Product Designer: Privilege escalation or authentication bypass
Fancy Product Designer is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated subscriber account. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Oct 20, 2023 |
CVE-2021-4335
Fancy Product Designer: A security weakness
Fancy Product Designer is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.3
NVD6.3
|
| Apr 19, 2022 |
CVE-2021-4096
Fancy Product Designer: Cross-site request forgery
Fancy Product Designer is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Feb 16, 2022 |
CVE-2021-4134
Fancy Product Designer: SQL injection
Fancy Product Designer is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.2
NVD4.9
|
| Jun 21, 2021 |
CVE-2021-24370
Fancy Product Designer: Code execution
Fancy Product Designer is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVEPending
NVD9.8
|