Information Disclosure Vulnerability in Fancy Product Designer Plugin for WordPress
CVE-2025-13439
What is CVE-2025-13439?
The Fancy Product Designer plugin for WordPress is susceptible to an information disclosure vulnerability due to inadequate validation of user-input within the 'url' parameter of the fpd_custom_upload_file AJAX action. This vulnerability permits unauthenticated attackers to potentially access sensitive files, including the configuration file wp-config.php, by exploiting the getimagesize() function without proper sanitization. Although PHP 8+ mitigates direct exploitation via PHP filter chains, risks remain in PHP 7.x environments and can be exacerbated by a time-of-check to time-of-use (TOCTOU) race condition, which is also an identified issue within this plugin.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Fancy Product Designer * <= 6.4.8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved