Printcart Web to Print Product Designer for WooCommerce - Unauthenticated Arbitrary File Deletion
criticalOtherThe Printcart Web to Print Product Designer plugin for WooCommerce (versions up to 2.5.2) contains a critical vulnerability allowing unauthenticated attackers to delete arbitrary files on the server. Combined with a bypassable nonce mechanism, this flaw could enable deletion of critical files such as wp-config.php, potentially leading to remote code execution and full site compromise.
Updated Jul 6, 2026 · CVSS 9.1