CVE-2026-75098: Product Designer App <= 1.1.3 - Unauthenticated Arbitrary File Read via 'svg' Parameter in pdapp-render-design
The Product Designer App plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.3 via the 'svg' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The endpoint's only authentication gate relies on a nonce and token that are both publicly emitted as JavaScript globals on any page rendering the [pdapp-studio-page] shortcode, making them freely obtainable by anonymous visitors.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated visitor can potentially exploit it when a page rendering the [pdapp-studio-page] shortcode is publicly accessible. The nonce and token required by the endpoint are emitted as JavaScript globals on those pages.
What can an attacker access?
An attacker can use directory traversal through the svg parameter to read arbitrary files from the server. Files readable by the web-server process may expose sensitive information.
Which plugin versions are affected?
All Product Designer App versions through 1.1.3, including 1.1.3, are affected.