URL Manipulation and File Exposure in Printcart Web to Print Designer Plugin for WooCommerce
CVE-2025-15662

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 July 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2025-15662?

The Printcart Web to Print Product Designer plugin for WooCommerce prior to version 2.5.3 lacks proper validation of user-supplied URLs, which enables attackers to exploit this flaw and execute arbitrary server-side requests. This vulnerability allows unauthorized users to access sensitive local files, including those that may contain critical configuration data such as database credentials and secret keys. The absence of sufficient authorization checks exacerbates the risk, making internal resources vulnerable to unauthorized access.

Affected Version(s)

Printcart Web to Print Product Designer for WooCommerce 0 < 2.5.3

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

D01EXPLOIT OFFICIAL
WPScan
.