MEDIUM
CVE-2025-10268
CVSS
5.3
Description
The Printcart Web to Print Product Designer for WooCommerce WordPress plugin through 2.4.8 is vulnerable to path traversal which makes it possible for the attacker to retrieve the directory listing for arbitrary directories on the server.
Summary dbcve.org
The Printcart Web to Print Product Designer plugin for WordPress versions up to 2.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to retrieve directory listings from arbitrary directories on the server by manipulating path parameters.
Mitigation
Update the Printcart plugin to the latest version when available, and implement strict input validation with allowlist-based path restrictions to prevent directory traversal sequences.
EPSS Score
0.39%
Probability of exploitation in next 30 days
32.8th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.