CyberRota Analysis
AI-GeneratedThe Printcart Web to Print Product Designer plugin for WooCommerce prior to version 2.5.3 is vulnerable due to improper validation of user-supplied URLs, enabling unauthenticated attackers to access arbitrary local files, including sensitive configuration files. This could lead to exposure of database credentials and secret keys, posing a significant risk to the integrity and confidentiality of the affected WordPress installations. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential exploitation.
Original NVD Description
The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing unauthenticated attackers to read arbitrary local files (including configuration files containing database credentials and secret keys) and to make server-side requests to internal resources.