Vulnerabilities and security researches forprintcart-integration printcart-integration
Direction: ascendingMay 20, 2025
Printcart Web to Print Product Designer for WooCommerce # CVE-2025-47641
- CVE, Research URL
- Date
- May 23, 2025
- Research Description
- Unrestricted Upload of File with Dangerous Type vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce printcart-integration allows Upload a Web Shell to a Web Server.This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through <= 2.3.9.
- Affected versions
-
max 2.4.0.
- Status
-
vulnerable
May 27, 2025
Printcart Web to Print Product Designer for WooCommerce # CVE-2025-47640
- CVE, Research URL
- Date
- May 23, 2025
- Research Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce printcart-integration allows SQL Injection.This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through <= 2.4.0.
- Affected versions
-
max 2.4.1.
- Status
-
vulnerable
Jul 05, 2025
Printcart Web to Print Product Designer for WooCommerce # CVE-2025-24780
- CVE, Research URL
- Date
- Jul 04, 2025
- Research Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce printcart-integration allows SQL Injection.This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through <= 2.4.0.
- Affected versions
-
max 2.4.1.
- Status
-
vulnerable
Apr 25, 2026
Printcart Web to Print Product Designer for WooCommerce # CVE-2025-57917
- CVE, Research URL
- Date
- Sep 23, 2025
- Research Description
- Missing Authorization vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce printcart-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through <= 2.4.8.
- Affected versions
-
max 2.4.8.
- Status
-
vulnerable
Jul 01, 2026
Printcart Web to Print Product Designer for WooCommerce # CVE-2025-10268
- CVE, Research URL
- Date
- Jun 26, 2026
- Research Description
- The Printcart Web to Print Product Designer for WooCommerce WordPress plugin through 2.4.8 is vulnerable to path traversal which makes it possible for the attacker to retrieve the directory listing for arbitrary directories on the server.
- Affected versions
-
max 2.4.8.
- Status
-
vulnerable
Jul 04, 2026
Printcart Web to Print Product Designer for WooCommerce # CVE-2026-9725
- CVE, Research URL
- Date
- Jul 03, 2026
- Research Description
- The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is due to insufficient path validation in the store_design_data() function, which constructs a filesystem path from the user-supplied 'nbd_item_key' POST parameter sanitized only with sanitize_text_field() — which does not strip path traversal sequences — and then passes that path directly to Nbdesigner_IO::delete_folder() and PHP's rename(). The nonce protecting the nbd_save_customer_design AJAX action is freely obtainable by unauthenticated users via the nbd_check_use_logged_in endpoint. This makes it possible for unauthenticated attackers to delete arbitrary files on the affected site's server which may make remote code execution possible.
- Affected versions
-
max 2.5.3.
- Status
-
vulnerable
Jul 31, 2026
Printcart Web to Print Product Designer for WooCommerce # CVE-2025-15662
- CVE, Research URL
- Date
- Jul 27, 2026
- Research Description
- The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing unauthenticated attackers to read arbitrary local files (including configuration files containing database credentials and secret keys) and to make server-side requests to internal resources.
- Affected versions
-
max 2.5.3.
- Status
-
vulnerable
Sep 19, 2026
Printcart Web to Print Product Designer for WooCommerce # CVE-2026-14323
- CVE, Research URL
- Date
- Sep 18, 2026
- Research Description
- The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.5 via the 'mockups' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. A valid nonce is obtainable by unauthenticated users via the companion nbd_check_use_logged_in nopriv AJAX endpoint, which freely mints and returns a nbdesigner-get-data nonce to any visitor; additionally, if the NBDESIGNER_ENABLE_NONCE constant is disabled, even this nonce gate is bypassed entirely.
- Affected versions
-
max 2.8.6.
- Status
-
vulnerable