CVE-2025-15526 affects the Fancy Product Designer plugin for WordPress, specifically versions up to and including 6.4.8. It's a Full Path Disclosure vulnerability caused by improper error handling in the PDF upload feature, exposing server filesystem paths and stack traces. This vulnerability has a CVSS score of 5.3 (Medium), indicating a low-complexity attack requiring no authentication, but its direct impact is limited to information disclosure, which can aid in further attacks. There is currently no public exploit code available, nor any evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 6.4.8CPE match | cpe:2.3:a:radykal:fancy_product_designer:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.