🔐 CVE Alert

CVE-2026-14323

HIGH 7.5

Printcart Web to Print Product Designer for WooCommerce <= 2.8.5 - Unauthenticated Arbitrary File Read via 'folder' and 'mockups' Parameters

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.5 via the 'mockups' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. A valid nonce is obtainable by unauthenticated users via the companion nbd_check_use_logged_in nopriv AJAX endpoint, which freely mints and returns a nbdesigner-get-data nonce to any visitor; additionally, if the NBDESIGNER_ENABLE_NONCE constant is disabled, even this nonce gate is bypassed entirely.

CWE CWE-22
Vendor printcart
Product printcart store – web to print product designer for woocommerce
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for printcart printcart store – web to print product designer for woocommerce

Be the first to know when new high vulnerabilities affecting printcart printcart store – web to print product designer for woocommerce are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

printcart / Printcart Store – Web to Print Product Designer for WooCommerce
0 ≤ 2.8.5

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/6d050a44-41ac-46ac-ba2e-406bfaebec69?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/printcart-integration/tags/2.5.2/includes/class.resource.php#L220 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/printcart-integration/tags/2.5.2/includes/class.resource.php#L217 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/printcart-integration/tags/2.5.2/includes/class.resource.php#L27 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/printcart-integration/tags/2.5.2/includes/class.nbdesigner.php#L213 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?reponame=&old=3658512%40printcart-integration&new=3658512%40printcart-integration

Credits

Spy0x7