High severity7.2NVD Advisory· Published Feb 16, 2022· Updated Jun 17, 2026
CVE-2021-4134
CVE-2021-4134
Description
The Fancy Product Designer WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the ID parameter found in the ~/inc/api/class-view.php file which allows attackers with administrative level permissions to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 4.7.4.
Affected products
3- cpe:2.3:a:radykal:fancy_product_designer:*:*:*:*:*:wordpress:*:*Range: <4.7.5
- Range: <=4.7.4
- Fancy Product Designer/Fancy Product Designerv5Range: 4.7.4
Patches
Vulnerability mechanics
References
2- www.wordfence.com/vulnerability-advisories/nvdExploitThird Party Advisory
- support.fancyproductdesigner.com/support/discussions/topics/13000031264nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.