Product Designer App Plugin Vulnerability (CVE-2026-75098)

On this page

Security Alert Summary

The Product Designer App plugin for WordPress contains a directory traversal vulnerability in the svg parameter that affects all versions up to and including 1.1.3. An unauthenticated attacker can read arbitrary files on the server. The endpoint’s only authentication relies on a nonce and token that are emitted as JavaScript globals on any page rendering the [pdapp-studio-page] shortcode, making those values obtainable by anonymous visitors.


CVE Details

  • CVE ID: CVE-2026-75098
  • Affected product: Product Designer App plugin for WordPress
  • Affected versions: All versions up to and including 1.1.3
  • Published: September 30, 2026 at 9:17:16 AM
  • Last modified: September 30, 2026 at 4:18:58 PM
  • CVSS v3.1: Base score 7.5 – HIGH; CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Authentication / privileges / user interaction: No authentication required (PR:N); no user interaction required (UI:N)
  • Primary impact: Confidentiality – HIGH; Integrity – NONE; Availability – NONE
  • Weakness: CWE-22 (Directory Traversal)

Technical Details

The plugin exposes an endpoint that accepts an svg parameter. Insufficient validation of this parameter allows directory traversal, enabling an attacker to request and read arbitrary files on the server. The endpoint’s authentication relies on a nonce and token that are output as JavaScript globals on pages that render the [pdapp-studio-page] shortcode, so an anonymous visitor can obtain those values from the page context.

Reference code locations provided in the advisory point to files within the plugin repository that handle front-end AJAX and helper functionality, including includes/productdesignerapp-front-ajax.php and includes/productdesignerapp-helpers.php, and a template script at templates/default/script/variants.php. The advisory indicates the authentication gate depends on the publicly emitted nonce and token rather than an access-restricted check, which is the primary reason the directory traversal can be exploited by unauthenticated users.

Successful exploitation permits reading file contents from the server. This can disclose sensitive configuration files, user data, or other information stored on the filesystem. The vulnerability does not, based on the provided information, indicate direct ability to modify files or execute code on the server.


How This Could Impact Your Website

On a multi-user WordPress site, an attacker who obtains arbitrary files could access sensitive data that affects different roles: the site owner may have configuration files exposed, internal staff or contractors could have their private data or exported resources leaked, and contributors or external users might have their email addresses or profile details exposed. Exposed email addresses and configuration details increase the risk of targeted phishing and social engineering against employees or contractors, and could reveal information useful for further attacks.

If you’re unsure whether your site is affected or how to assess your current user roles and plugins, it may be worth having a professional review of your setup.


Recommended Actions

  • Update the affected plugin as soon as a patched version is available.
  • Review and reduce unnecessary user roles, especially contributor-level accounts and any accounts with write access.
  • Enforce strong passwords and enable two-factor authentication for editor and administrator accounts.
  • Remove unused or unmaintained plugins to reduce attack surface.
  • Monitor site activity and server logs for unusual file access patterns or unexpected requests to plugin endpoints.

If youd like help reviewing your plugins, user roles, or overall WordPress security posture, our team at Freshy is happy to help.


References