Another top WordPress plugin was found with critical security flaws


  • Researchers from Patchstack find two new bugs in Fancy Product Designer
  • The Radykal-built WordPress plugin has more than 20,000 active users
  • The flaws allowed remote code execution, arbitrary file uploads and more

A popular WordPress plugin was found with two critical vulnerabilities that allow threat actors to upload files, manipulate databases and essentially take over compromised websites.

To make matters worse, the vulnerabilities remained in the code for more than half a year, despite the developers being notified and actively working on new versions in the meantime.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top