Stored Cross-Site Scripting in Fancy Product Designer Plugin for WordPress
CVE-2026-84281

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
25 September 2026

What is CVE-2026-84281?

The Fancy Product Designer plugin for WordPress is affected by a Stored Cross-Site Scripting vulnerability due to inadequate input validation and output escaping. Unauthenticated attackers can exploit this flaw through the 'productTitle' field in the '_fpd_data' Order Item Meta, enabling them to inject malicious scripts. The issue arises from the unprotected fpd_save_order AJAX action which lacks the necessary nonce or capability checks. The current sanitization process using strip_tags() can be bypassed by submitting JSON unicode escape sequences, resulting in the execution of arbitrary scripts on affected pages when accessed by users.

Affected Version(s)

Fancy Product Designer 0 <= 6.5.2

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

h0xilo
.