PT-2025-51468 · WordPress · Fancy Product Designer

Muhammad Zeeshan

·

Publicado

2025-12-16

·

Atualizado

2025-12-17

·

CVE-2025-13231

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Fancy Product Designer versions prior to 6.4.9
Description The software is susceptible to a Server-Side Request Forgery (SSRF) issue. This is caused by a time-of-check/time-of-use (TOCTOU) race condition within the 'url' parameter of the fpd custom uplod file AJAX action. The validation process uses getimagesize() followed by file get contents() on the same URL, creating a timing gap that allows attackers to redirect requests to arbitrary internal or external URLs.
Recommendations Update The Fancy Product Designer plugin to version 6.4.9 or later.

Correção

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-13231

Produtos afetados

Fancy Product Designer