cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forprintcart-integration printcart-integration

Direction: descending
Sep 19, 2026

Printcart Web to Print Product Designer for WooCommerce # CVE-2026-14323

CVE, Research URL

CVE-2026-14323

Date
Sep 18, 2026
Research Description
The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.5 via the 'mockups' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. A valid nonce is obtainable by unauthenticated users via the companion nbd_check_use_logged_in nopriv AJAX endpoint, which freely mints and returns a nbdesigner-get-data nonce to any visitor; additionally, if the NBDESIGNER_ENABLE_NONCE constant is disabled, even this nonce gate is bypassed entirely.
Affected versions
max 2.8.6.
Status
vulnerable
Jul 31, 2026

Printcart Web to Print Product Designer for WooCommerce # CVE-2025-15662

CVE, Research URL

CVE-2025-15662

Date
Jul 27, 2026
Research Description
The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing unauthenticated attackers to read arbitrary local files (including configuration files containing database credentials and secret keys) and to make server-side requests to internal resources.
Affected versions
max 2.5.3.
Status
vulnerable
Jul 04, 2026

Printcart Web to Print Product Designer for WooCommerce # CVE-2026-9725

CVE, Research URL

CVE-2026-9725

Date
Jul 03, 2026
Research Description
The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is due to insufficient path validation in the store_design_data() function, which constructs a filesystem path from the user-supplied 'nbd_item_key' POST parameter sanitized only with sanitize_text_field() — which does not strip path traversal sequences — and then passes that path directly to Nbdesigner_IO::delete_folder() and PHP's rename(). The nonce protecting the nbd_save_customer_design AJAX action is freely obtainable by unauthenticated users via the nbd_check_use_logged_in endpoint. This makes it possible for unauthenticated attackers to delete arbitrary files on the affected site's server which may make remote code execution possible.
Affected versions
max 2.5.3.
Status
vulnerable
Jul 01, 2026

Printcart Web to Print Product Designer for WooCommerce # CVE-2025-10268

CVE, Research URL

CVE-2025-10268

Date
Jun 26, 2026
Research Description
The Printcart Web to Print Product Designer for WooCommerce WordPress plugin through 2.4.8 is vulnerable to path traversal which makes it possible for the attacker to retrieve the directory listing for arbitrary directories on the server.
Affected versions
max 2.4.8.
Status
vulnerable
Apr 25, 2026

Printcart Web to Print Product Designer for WooCommerce # CVE-2025-57917

CVE, Research URL

CVE-2025-57917

Date
Sep 23, 2025
Research Description
Missing Authorization vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce printcart-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through <= 2.4.8.
Affected versions
max 2.4.8.
Status
vulnerable
Jul 05, 2025

Printcart Web to Print Product Designer for WooCommerce # CVE-2025-24780

CVE, Research URL

CVE-2025-24780

Date
Jul 04, 2025
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce printcart-integration allows SQL Injection.This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through <= 2.4.0.
Affected versions
max 2.4.1.
Status
vulnerable
May 27, 2025

Printcart Web to Print Product Designer for WooCommerce # CVE-2025-47640

CVE, Research URL

CVE-2025-47640

Date
May 23, 2025
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce printcart-integration allows SQL Injection.This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through <= 2.4.0.
Affected versions
max 2.4.1.
Status
vulnerable
May 20, 2025

Printcart Web to Print Product Designer for WooCommerce # CVE-2025-47641

CVE, Research URL

CVE-2025-47641

Date
May 23, 2025
Research Description
Unrestricted Upload of File with Dangerous Type vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce printcart-integration allows Upload a Web Shell to a Web Server.This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through <= 2.3.9.
Affected versions
max 2.4.0.
Status
vulnerable