Stored Cross-Site Scripting Vulnerability in Fancy Product Designer for WordPress
CVE-2025-12570
What is CVE-2025-12570?
The Fancy Product Designer plugin for WordPress is subject to a Stored Cross-Site Scripting vulnerability when handling SVG file uploads. This issue arises from inadequate input sanitization and output escaping in crucial files, namely data-to-image.php and pdf-to-image.php. The flaw allows unauthenticated attackers to inject arbitrary scripts into web pages, potentially executing malicious code every time users access the compromised SVG files. Users of the affected versions should consider immediate updates and implementing security measures to mitigate potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Fancy Product Designer * <= 6.4.8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved