CVE-2026-9725Disclosure

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is due to insufficient path validation in the store_design_data() function, which constructs a filesystem path from the user-supplied 'nbd_item_key' POST parameter sanitized only with sanitize_text_field() — which does not strip path traversal sequences — and then passes that path directly to Nbdesigner_IO::delete_folder() and PHP's rename(). The nonce protecting the nbd_save_customer_design AJAX action is freely obtainable by unauthenticated users via the nbd_check_use_logged_in endpoint. This makes it possible for unauthenticated attackers to delete arbitrary files on the affected site's server which may make remote code execution possible.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-03: 2Patch / Workaround · 2026-07-03: 1Technical Details · 2026-07-03: 207-03
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Full discourse2 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-9725 — CVSS 9.1/10 █████████░ The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/6Fu6SgftQC

    Post summary

    The tweet alerts about CVE‑2026‑9725, highlighting an arbitrary file vulnerability with a high CVSS score and urges users to apply a patch; no exploit or active attack evidence is provided.

    10000117
    64 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Unauthenticated arbitrary file deletion via path manipulation in store_design_data() (CVE-2026-9725) CVE-2026-9725 is an arbitrary file deletion issue in the Printcart Web to Print Product Designer for WooCommerce WordPress plugin, specifically in the store_design_data() function that builds filesystem paths from the nbd_item_key POST parameter. The root cause is insufficient path validation leading to a path traversal style flaw in file operations (delete/rename) on attacker-influenced paths. An unauthenticated attacker can first obtain a valid nonce via the exposed nbd_check_use_logged_in endpoint, then send crafted POST requests to manipulate path resolution and trigger deletion/renaming of files on the server. Real-world impact ranges from destructive denial of service and site takeover via deletion of critical files to potential remote code execution if the attacker can remove/replace security controls or influence executable PHP/plugin files. 👉 Affected: Printcart Web to Print Product Designer for WooCommerce <= 2.5.2 | Upgrade to No fix yet — treat as suspicious

    Post summary

    The post discloses CVE‑2026‑9725, an unauthenticated arbitrary file deletion flaw in Printcart’s WooCommerce plugin, detailing its mechanics, potential impact, and that no fix is yet available.

    0000094
    236 followersView on X

Explore more