CVE-2025-15662
Description
The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing unauthenticated attackers to read arbitrary local files (including configuration files containing database credentials and secret keys) and to make server-side requests to internal resources.
Metadata
Severity & Metrics
No CVSS data available.
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Unknown | Printcart Web to Print Product Designer for WooCommerce | — | 0 < 2.5.3 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | CWE-918 Server-Side Request Forgery (SSRF) |