Signal is active with 2 mentions in latest observed window
Immediate actions
Patch affected systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is due to insufficient path validation in the store_design_data() function, which constructs a filesystem path from the user-supplied 'nbd_item_key' POST parameter sanitized only with sanitize_text_field() — which does not strip path traversal sequences — and then passes that path directly to Nbdesigner_IO::delete_folder() and PHP's rename(). The nonce protecting the nbd_save_customer_design AJAX action is freely obtainable by unauthenticated users via the nbd_check_use_logged_in endpoint. This makes it possible for unauthenticated attackers to delete arbitrary files on the affected site's server which may make remote code execution possible.
🚨 CVE-2026-9725 — CVSS 9.1/10
█████████░
The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File...
Severity: CRITICAL
Patch now.
#cybersecurity#CVE https://t.co/6Fu6SgftQC
Post summary
The tweet alerts about CVE‑2026‑9725, highlighting an arbitrary file vulnerability with a high CVSS score and urges users to apply a patch; no exploit or active attack evidence is provided.
🚨 CRITICAL - Unauthenticated arbitrary file deletion via path manipulation in store_design_data() (CVE-2026-9725)
CVE-2026-9725 is an arbitrary file deletion issue in the Printcart Web to Print Product Designer for WooCommerce WordPress plugin, specifically in the store_design_data() function that builds filesystem paths from the nbd_item_key POST parameter. The root cause is insufficient path validation leading to a path traversal style flaw in file operations (delete/rename) on attacker-influenced paths. An unauthenticated attacker can first obtain a valid nonce via the exposed nbd_check_use_logged_in endpoint, then send crafted POST requests to manipulate path resolution and trigger deletion/renaming of files on the server. Real-world impact ranges from destructive denial of service and site takeover via deletion of critical files to potential remote code execution if the attacker can remove/replace security controls or influence executable PHP/plugin files.
👉 Affected: Printcart Web to Print Product Designer for WooCommerce <= 2.5.2 | Upgrade to No fix yet — treat as suspicious
Post summary
The post discloses CVE‑2026‑9725, an unauthenticated arbitrary file deletion flaw in Printcart’s WooCommerce plugin, detailing its mechanics, potential impact, and that no fix is yet available.