Another top WordPress plugin that contains critical security flaws


  • Patchstack researchers discover two new flaws in Fancy Product Designer
  • The WordPress plugin built by Radykal has over 20,000 active users
  • The flaws allowed remote code execution, arbitrary file uploads, and more

A popular WordPress plugin has been found to contain two critical vulnerabilities that allow threat actors to upload files, tamper with databases, and essentially take over compromised websites.

To make matters worse, the vulnerabilities remained in the code for more than six months, despite the developers being informed of them and actively working on new versions in the meantime.