Executive brief
Shirt Product Designer for WooCommerce is a WordPress plugin that allows merchants to offer customizable t-shirt design tools to customers. An unauthenticated vulnerability in version 1.0.4 allows attackers to bypass access controls and view or access data they should not be permitted to see, potentially exposing customer information, orders, or sensitive shop data without requiring login credentials.
Technical details
This vulnerability is a broken access control flaw (OWASP A1) in the Shirt Product Designer for WooCommerce plugin version 1.0.4. The vulnerability is unauthenticated, meaning an attacker does not need valid WordPress credentials to exploit it. An attacker can leverage this flaw to bypass authorization checks and access restricted pages or perform unauthorized actions, such as viewing other users' data or design configurations. The exact vulnerable endpoint and mechanism are not specified in the advisory. No official patch is currently available; users should upgrade to a patched version when released or disable the plugin.
Affected products
- WordPress Shirt Product Designer for WooCommerce 1.0.4
Timeline
- 2026-09-09: disclosed
- 2026-09-10: advisory