PT-2026-3216 · WordPress · Fancy Product Designer

Muhammad Zeeshan

·

Published

2026-01-16

·

Updated

2026-01-16

·

CVE-2025-15526

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fancy Product Designer plugin for WordPress versions prior to 6.4.9
Description The software is susceptible to a Full Path Disclosure issue. This stems from improper error handling within the PDF upload functionality, which reveals server filesystem paths and stack traces in error messages. An unauthenticated attacker can potentially retrieve the full path of the web application. The disclosed information, while not directly damaging, can assist in facilitating other attacks.
Recommendations Update Fancy Product Designer plugin to version 6.4.9 or later.

Fix

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2025-15526

Affected Products

Fancy Product Designer