Skip to main content
Vulnerability Database/CVE-2026-75098

CVE-2026-75098: WordPress Product Designer Path Traversal

CVE-2026-75098 is a path traversal vulnerability in the WordPress Product Designer App plugin allowing unauthenticated attackers to read arbitrary files on the server. This article covers technical details, affected versions, impact, and mitigation strategies.

Published:

CVE-2026-75098 Overview

CVE-2026-75098 is a directory traversal vulnerability [CWE-22] in the Product Designer App plugin for WordPress. The flaw affects all versions up to and including 1.1.3 and stems from unsafe handling of the svg parameter. Unauthenticated attackers can read arbitrary files from the underlying server, exposing configuration files, credentials, and other sensitive data.

The endpoint is protected only by a nonce and token, but both values are publicly emitted as JavaScript globals on any page that renders the [pdapp-studio-page] shortcode. Anonymous visitors can harvest these tokens from page source and abuse the AJAX endpoint without authentication.

Critical Impact

Unauthenticated attackers can read arbitrary files on WordPress servers running vulnerable versions of the Product Designer App plugin, potentially exposing wp-config.php, private keys, and application secrets.

Affected Products

  • Product Designer App plugin for WordPress — versions up to and including 1.1.3
  • WordPress sites rendering the [pdapp-studio-page] shortcode
  • Any hosting environment where the vulnerable plugin is active

Discovery Timeline

  • 2026-09-30 - CVE CVE-2026-75098 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-75098

Vulnerability Analysis

The Product Designer App plugin exposes a front-end AJAX endpoint that accepts an svg parameter and serves file contents based on the supplied path. The handler in productdesignerapp-front-ajax.php passes the parameter to helper routines in productdesignerapp-helpers.php without normalizing or restricting the path.

Because the value is not constrained to the plugin's asset directory, attackers can supply traversal sequences such as ../../../../ to escape the intended base path. The server then reads and returns the contents of arbitrary files accessible to the web server user.

The authentication gate is ineffective in practice. Both the nonce and the accompanying token used to authorize the request are emitted as JavaScript globals in the template at templates/default/script/variants.php. Any unauthenticated visitor loading a page with the plugin's shortcode receives working credentials in the HTML response.

Root Cause

The root cause is missing path canonicalization and validation on the svg request parameter, combined with a client-exposed authorization token. The helper functions concatenate user input into a filesystem path and read the resulting file without confirming it resides within an allowed directory.

Attack Vector

An unauthenticated remote attacker first requests any public page that renders the [pdapp-studio-page] shortcode and extracts the nonce and token from the response body. The attacker then issues an admin-ajax.php request supplying the harvested credentials and a traversal payload in the svg parameter. The server returns the contents of the targeted file, enabling disclosure of wp-config.php, SSH keys, session data, or other secrets.

See the Wordfence Vulnerability Report and the referenced WordPress Plugin AJAX Function for the vulnerable code path.

Detection Methods for CVE-2026-75098

Indicators of Compromise

  • Requests to wp-admin/admin-ajax.php containing the plugin's action name with an svg parameter that includes ../ sequences or URL-encoded variants such as %2e%2e%2f.
  • Access log entries showing successful responses containing PHP source or configuration-file markers such as DB_PASSWORD or AUTH_KEY.
  • Repeated anonymous requests to pages hosting the [pdapp-studio-page] shortcode followed by AJAX calls from the same source IP.

Detection Strategies

  • Deploy a Web Application Firewall (WAF) rule that blocks traversal patterns in the svg query parameter for any Product Designer App AJAX endpoint.
  • Alert when admin-ajax.php responses returning file-like content exceed a size threshold or include known secrets patterns.
  • Correlate shortcode page views with subsequent AJAX calls that carry the harvested nonce, flagging outlier behavior from unauthenticated sessions.

Monitoring Recommendations

  • Enable verbose logging on the WordPress reverse proxy or WAF for all admin-ajax.php traffic referencing the plugin.
  • Monitor filesystem access to wp-config.php and other sensitive files by the PHP-FPM or web server user account.
  • Track outbound bandwidth spikes from web hosts, which can indicate bulk file exfiltration through repeated traversal requests.

How to Mitigate CVE-2026-75098

Immediate Actions Required

  • Update the Product Designer App plugin to a version later than 1.1.3 as soon as the vendor releases a fixed build.
  • If no patch is available, deactivate and remove the plugin from all WordPress sites until a fix is published.
  • Rotate any credentials, API keys, or secrets stored in wp-config.php that may have been exposed on internet-facing sites.

Patch Information

No fixed version is referenced in the NVD entry at publication time. Administrators should track vendor releases and the Wordfence Vulnerability Report for updated patch guidance. Consult the vulnerable helper code at productdesignerapp-helpers.php line 261 and line 2867 when validating vendor fixes.

Workarounds

  • Remove the [pdapp-studio-page] shortcode from all public pages to prevent nonce and token harvesting by anonymous visitors.
  • Configure a WAF rule to block requests to the plugin's AJAX action when the svg parameter contains path separators or traversal sequences.
  • Restrict web server filesystem permissions so the PHP process cannot read sensitive files outside the WordPress webroot.
bash
# Example ModSecurity rule to block traversal in the svg parameter
SecRule ARGS:svg "@rx (\.\./|%2e%2e%2f|%2e%2e/)" \
  "id:1075098,phase:2,deny,status:403,log,\
   msg:'CVE-2026-75098 Product Designer App traversal attempt'"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.