← WordPress Vulnerabilities
WordPress security by component

Printcart Web to Print Product Designer for WooCommerce

Printcart Web to Print Product Designer for WooCommerce is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 8.6.

Plugin slug: printcart-web-to-print-product-designer-for-woocommerce

CVE-2025-15662: Printcart unauthenticated URL fetch permits local file read and SSRF

Printcart Web to Print Product Designer for WooCommerce before 2.5.3 exposes an unauthenticated server-side URL fetch without restricting the requested scheme or destination. An attacker can make the plugin read local files such as wp-config.php, exposing database credentials and WordPress secret keys, or send requests to internal network services. The CNA record does not disclose the handler, action, URL parameter or fetch function.

PublishedJul 27, 2026
Known safe version2.5.3
Safe version
Jul 27, 2026 CVE-2025-15662
Printcart unauthenticated URL fetch permits local file read and SSRF
Printcart Web to Print Product Designer for WooCommerce before 2.5.3 exposes an unauthenticated server-side URL fetch without restricting the requested scheme or destination. An attacker can make the plugin read local files such as wp-config.php, exposing database credentials and WordPress secret keys, or send requests to internal network services. The CNA record does not disclose the handler, action, URL parameter or fetch function.
2.5.3
CVE8.6
NVDPending
Jun 26, 2026 CVE-2025-10268
Printcart Web to Print Product Designer for WooCommerce: Filesystem traversal
Printcart Web to Print Product Designer for WooCommerce is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 2.4.8.
> 2.4.8
CVE5.3
NVDPending