Fancy Product Designer

Explore Fancy Product Designer vulnerabilities across all versions. Currently tracking 16 known vulnerabilities, including severity, impact, and patch status.

01234567891018.11.2020Today18.11.20206.4Fancy Product Designer <= 4.5.0 - Stored Cross-Site Scripting CVSS 6.4 · 18.11.202001.06.20219.8Fancy Product Designer <= 4.6.8 - Unauthenticated Arbitrary File Upload CVSS 9.8 · 01.06.202108.02.20227.2Fancy Product Designer <= 4.7.4 - Admin+ SQL Injection CVSS 7.2 · 08.02.202214.04.20228.8Fancy Product Designer <= 4.7.5 - Cross-Site Request Forgery to Arbitrary File Upload CVSS 8.8 · 14.04.202205.04.20236.3Fancy Product Designer <= 4.6.9 - Insufficient Authorization on Mulitple AJAX Actions CVSS 6.3 · 05.04.20238.8Fancy Product Designer <= 4.6.9 - Insufficient Authorization to Arbitrary Options Update via fpd_update_options CVSS 8.8 · 05.04.202320.02.20249.1Fancy Product Designer <= 6.1.4 - Authenticated (Admin+) SQL Injection CVSS 9.1 · 20.02.202425.03.20244.4Fancy Product Designer < 6.1.81 - Authenticated (Admin+) Stored Cross-Site Scripting via Product Title CVSS 4.4 · 25.03.202415.04.20244.4Fancy Product Designer < 6.1.81 - Authenticated (Admin+) Stored Cross-Site Scripting via License Field CVSS 4.4 · 15.04.202426.04.20246.1Fancy Product Designer <= 6.1.7 - Reflected Cross-Site Scripting CVSS 6.1 · 26.04.202403.01.20257.5Fancy Product Designer <= 6.4.3 - Unauthenticated SQL Injection CVSS 7.5 · 03.01.20259.8Fancy Product Designer <= 6.4.3 - Unauthenticated Arbitrary File Upload CVSS 9.8 · 03.01.202511.12.20257.2Fancy Product Designer <= 6.4.8 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload CVSS 7.2 · 11.12.202515.12.20255.9Fancy Product Designer | WooCommerce WordPress <= 6.4.8 - Unauthenticated Information Disclosure and PHAR Deserialization via 'url' Parameter CVSS 5.9 · 15.12.20255.3Fancy Product Designer | WooCommerce WordPress <= 6.4.8 - Unauthenticated Full Path Disclosure via 'pdf' Parameter CVSS 5.3 · 15.12.20256.5Fancy Product Designer | WooCommerce WordPress <= 6.4.8 - Unauthenticated Server-Side Request Forgery via Race Condition CVSS 6.5 · 15.12.2025

Strategic Overview

Avg CVSSHigh
7.1/ 10
Patch Coverage100%
Open

0

Fixed

16

Get automatic notifications for all Fancy Product Designer vulnerabilities before they are exploited.

Vulnerability Records

16 records
2025-12-15 00:00CVE-2025-13439
5.9
Medium
Muhammad Zeeshan (Xib3rR4dAr)Yes
2025-12-15 00:00CVE-2025-15526
5.3
Medium
Muhammad Zeeshan (Xib3rR4dAr)Yes
2025-12-15 00:00CVE-2025-13231
6.5
Medium
Muhammad Zeeshan (Xib3rR4dAr)Yes
2025-12-11 18:11CVE-2025-12570
7.2
High
Muhammad Zeeshan (Xib3rR4dAr)Yes
2025-01-03 00:00CVE-2024-51818
7.5
High
Rafie MuhammadYes
2025-01-03 00:00CVE-2024-51919
9.8
Critical
Rafie MuhammadYes
2024-04-26 00:00CVE-2024-0905
6.1
Medium
Bob MatyasYes
2024-04-15 00:00CVE-2024-0904
4.4
Medium
Bob MatyasYes
2024-03-25 00:00CVE-2024-0902
4.4
Medium
Bob MatyasYes
2024-02-20 00:00CVE-2024-0365
9.1
Critical
Ivan Spiridonov (xbz0n)Yes
Showing 1–10 of 16 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C