CVE-2025-15526 Details
Description
The Fancy Product Designer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 6.4.8. This is due to improper error handling in the PDF upload functionality that exposes server filesystem paths and stack traces in error messages. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
A full path disclosure vulnerability has been identified in the Fancy Product Designer plugin for WordPress, affecting all versions through 6.4.8. The issue arises from inadequate error handling in the PDF upload feature, which inadvertently reveals server filesystem paths and stack traces in error messages. This vulnerability allows unauthenticated attackers to obtain the full path of the web application, potentially facilitating further attacks. However, the disclosed information is not immediately harmful and would require the presence of another vulnerability to exploit an affected website.
Users are advised to update the Fancy Product Designer plugin to version 6.5.0 or a newer patched version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 16, 2026CISA-ADP
Assessed Jan 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-209 | Generation of Error Message Containing Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Fancy Product Designer | <= 6.4.8 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 16, 2026 | New CVE Received | [email protected] |
Volerion