High severity8.8NVD Advisory· Published Apr 19, 2022· Updated Jun 17, 2026
CVE-2021-4096
CVE-2021-4096
Description
The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import class that makes it possible for attackers to upload malicious files that could be used to gain webshell access to a server in versions up to, and including, 4.7.5.
Affected products
3- cpe:2.3:a:radykal:fancy_product_designer:*:*:*:*:*:wordpress:*:*Range: <=4.7.5
- Range: <=4.7.5
- fancy-product-designer/Fancy Product Designerv5Range: 4.7.5
Patches
Vulnerability mechanics
References
2- support.fancyproductdesigner.com/support/discussions/topics/13000031615nvdRelease NotesVendor Advisory
- www.wordfence.com/vulnerability-advisories/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.