SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2025-15662

HIGH · CVSS 8.6 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The Printcart Web to Print Product Designer plugin for WooCommerce prior to version 2.5.3 is vulnerable due to improper validation of user-supplied URLs, enabling unauthenticated attackers to access arbitrary local files, including sensitive configuration files. This could lead to exposure of database credentials and secret keys, posing a significant risk to the integrity and confidentiality of the affected WordPress installations. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2025-15662
Severity
HIGH
CVSS
8.6
EPSS
0.32%
WordPress

Original NVD Description

The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing unauthenticated attackers to read arbitrary local files (including configuration files containing database credentials and secret keys) and to make server-side requests to internal resources.