MEDIUM

CVE-2025-10268

2026-06-26 CVSS v3.1
CVSS
5.3

Description

The Printcart Web to Print Product Designer for WooCommerce WordPress plugin through 2.4.8 is vulnerable to path traversal which makes it possible for the attacker to retrieve the directory listing for arbitrary directories on the server.

Summary dbcve.org

The Printcart Web to Print Product Designer plugin for WordPress versions up to 2.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to retrieve directory listings from arbitrary directories on the server by manipulating path parameters.

Mitigation

Update the Printcart plugin to the latest version when available, and implement strict input validation with allowlist-based path restrictions to prevent directory traversal sequences.

EPSS Score

0.39%
Probability of exploitation in next 30 days
32.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE