---
id: CVE-2025-10268
title: >-
  The Printcart Web to Print Product Designer for WooCommerce WordPress plugin
  through 2.4.8 is vulnerable to path traversal which makes it possible for the
  attacker to retrieve the directory listing for arbitrary directories on the
  server.
summary: >-
  The Printcart Web to Print Product Designer for WooCommerce WordPress plugin
  through 2.4.8 is vulnerable to path traversal which makes it possible for the
  attacker to retrieve the directory listing for arbitrary directories on the
  server.
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
published: '2026-06-26'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:10:00.190'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-10268'
references:
  - url: 'https://wpscan.com/vulnerability/0cff6fb3-339b-4eb6-969b-b3a43613cc71/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00388
epssPercentile: 0.30399
ingestedAt: '2026-09-30T21:25:07.790Z'
---

## Overview

The Printcart Web to Print Product Designer for WooCommerce WordPress plugin through 2.4.8 is vulnerable to path traversal which makes it possible for the attacker to retrieve the directory listing for arbitrary directories on the server.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
