Another Major WordPress Plugin That Has Critical Security Flaws


  • Patchstack researchers find two new flaws in Fancy Product Designer
  • WordPress plugin created by Radykal has over 20,000 active users
  • Flaws allowed remote code execution, arbitrary file uploads, and more

A popular WordPress plugin was discovered to have two critical vulnerabilities that allow threat actors to upload files, manipulate databases, and essentially take over compromised websites.

To make matters worse, the vulnerabilities remained in the code for more than half a year, despite the developers being notified and actively working on new versions in the meantime.

Leave a Comment

Your email address will not be published. Required fields are marked *