Stored Cross-Site Scripting in Fancy Product Designer Plugin for WordPress
CVE-2026-84281
7.2HIGH
What is CVE-2026-84281?
The Fancy Product Designer plugin for WordPress is affected by a Stored Cross-Site Scripting vulnerability due to inadequate input validation and output escaping. Unauthenticated attackers can exploit this flaw through the 'productTitle' field in the '_fpd_data' Order Item Meta, enabling them to inject malicious scripts. The issue arises from the unprotected fpd_save_order AJAX action which lacks the necessary nonce or capability checks. The current sanitization process using strip_tags() can be bypassed by submitting JSON unicode escape sequences, resulting in the execution of arbitrary scripts on affected pages when accessed by users.
Affected Version(s)
Fancy Product Designer 0 <= 6.5.2