PitchPrint Security & Risk Analysis

wordpress.org/plugins/pitchprint

PitchPrint is a Web2Print plugin solution that provides an easy to use interface for creating artworks for prints like Business Card, TShirt, Banners.

400 active installs v11.3.0 PHP 7.4+ WP 3.8+ Updated Mar 23, 2026
customizergift-printphoto-albumprint-shopweb2print
94
A · Safe
CVEs total1
Unpatched0
Last CVEMar 10, 2026
Safety Verdict

Is PitchPrint Safe to Use in 2026?

Generally Safe

Score 94/100

PitchPrint has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Mar 10, 2026Updated 5mo ago
Risk Assessment

The "pitchprint" plugin v11.2.0 exhibits a mixed security posture. While it demonstrates good practices by using prepared statements for all SQL queries and avoiding bundled libraries, significant security concerns arise from its attack surface. All four identified AJAX handlers lack authentication checks, creating a direct pathway for potential unauthorized actions if any logic within these handlers can be exploited. The taint analysis also flagged one flow with unsanitized paths, indicating a potential for vulnerabilities if this path is user-controlled and not properly validated or escaped. The absence of any recorded vulnerability history might suggest a lack of past security issues or a low profile, but it does not inherently guarantee future security. The combination of a notable attack surface with unprotected entry points and a potential unsanitized path flow presents a moderate risk.

Key Concerns

  • Unprotected AJAX handlers
  • Flow with unsanitized paths
  • Output escaping issues
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
1 published

PitchPrint Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Critical
1

1 total CVE

CVE-2026-22448critical · 9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

PitchPrint <= 11.1.2 - Unauthenticated Arbitrary File Deletion

Mar 10, 2026 Patched in 11.2.0 (10d)
Version History

PitchPrint Release Timeline

v11.3.0Current
v11.2.0
v11.1.21 CVE
v11.1.11 CVE
v11.1.01 CVE
v11.0.111 CVE
v11.0.101 CVE
v11.0.91 CVE
v11.0.81 CVE
v11.0.71 CVE
v11.0.61 CVE
v11.0.51 CVE
v11.0.41 CVE
v11.0.31 CVE
v11.0.21 CVE
v10.2.21 CVE
v10.2.11 CVE
v10.2.01 CVE
v10.1.91 CVE
v10.1.81 CVE
Code Analysis
Analyzed Mar 16, 2026

PitchPrint Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
10
External Requests
3
Bundled Libraries
0

Output Escaping

36% escaped22 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<saveproject> (app\saveproject.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

PitchPrint Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

noprivwp_ajax_pitch_print_save_projectfunctions\general\init_hooks.php:58
authwp_ajax_pitch_print_save_projectfunctions\general\init_hooks.php:59
noprivwp_ajax_pitch_print_reset_projectfunctions\general\init_hooks.php:60
authwp_ajax_pitch_print_reset_projectfunctions\general\init_hooks.php:61
WordPress Hooks 22
actionadmin_menufunctions\general\init_hooks.php:10
actionadmin_initfunctions\general\init_hooks.php:13
filterplugin_action_links_pitchprint/pitchprint.phpfunctions\general\init_hooks.php:16
filterwoocommerce_product_data_tabsfunctions\general\init_hooks.php:19
actionwoocommerce_product_data_panelsfunctions\general\init_hooks.php:22
actionwoocommerce_process_product_metafunctions\general\init_hooks.php:25
filterwoocommerce_order_item_display_meta_keyfunctions\general\init_hooks.php:28
filterwoocommerce_order_item_get_formatted_meta_datafunctions\general\init_hooks.php:31
actionwoocommerce_admin_order_data_after_order_detailsfunctions\general\init_hooks.php:33
actionwp_headfunctions\general\init_hooks.php:38
actionwoocommerce_before_add_to_cart_buttonfunctions\general\init_hooks.php:40
filterwoocommerce_add_cart_item_datafunctions\general\init_hooks.php:43
filterwoocommerce_cart_item_thumbnailfunctions\general\init_hooks.php:46
filterwoocommerce_checkout_create_order_line_itemfunctions\general\init_hooks.php:49
actionwoocommerce_before_shop_loopfunctions\general\init_hooks.php:51
actionwoocommerce_before_my_accountfunctions\general\init_hooks.php:54
actionwoocommerce_order_status_changedfunctions\general\init_hooks.php:63
actionwoocommerce_new_orderfunctions\general\init_hooks.php:64
actionwoocommerce_email_order_detailsfunctions\general\init_hooks.php:67
actionplugins_loadedpitchprint.php:62
filterplugin_row_metapitchprint.php:74
actionbefore_woocommerce_initpitchprint.php:136
Maintenance & Trust

PitchPrint Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.6
Last updatedMar 23, 2026
PHP min version7.4
Downloads47K

Community Trust

Rating74/100
Number of ratings30
Active installs400
Developer Profile

PitchPrint Developer Profile

flexcubed

1 plugin · 400 total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
10 days
View full developer profile
Detection Fingerprints

How We Detect PitchPrint

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pitchprint/rsc/css/customizer.css/wp-content/plugins/pitchprint/rsc/css/woo.css/wp-content/plugins/pitchprint/rsc/css/front.css/wp-content/plugins/pitchprint/rsc/css/woo.min.css/wp-content/plugins/pitchprint/rsc/css/customizer.min.css/wp-content/plugins/pitchprint/rsc/css/front.min.css/wp-content/plugins/pitchprint/assets/css/customizer.css/wp-content/plugins/pitchprint/assets/css/woo.css+13 more
Script Paths
https://pitchprint.io/rsc/js/a.wp.jshttps://pitchprint.io/rsc/js/client.jshttps://pitchprint.io/rsc/js/cat-client.jshttps://pitchprint.io/rsc/js/noes6.jshttps://pitchprint.io/rsc/js/customizer.jshttps://pitchprint.io/rsc/js/front.js+4 more
Version Parameters
pitchprint_admin?ver=pitchprint_adminpitchprint_customizer_scriptspitchprint_front_scriptspitchprint_woo_scripts

HTML / DOM Fingerprints

CSS Classes
pitchprint_tabpp_modal_containerpp_modal_overlaypp_editor_containerpp_modal_dialogpp_upload_wrapperpp_upload_btnpp_customizer_options
HTML Comments
<!-- PitchPrint Editor HTML --><!-- PitchPrint Upload Wrapper --><!-- PitchPrint Customizer Options --><!-- PitchPrint Admin Settings -->+1 more
Data Attributes
data-pp-design-iddata-pp-product-iddata-pp-user-iddata-pp-editor-urldata-pp-upload-urldata-pp-design-upload-id+2 more
JS Globals
PitchPrintPPADMINPitchPrintCustomizerPitchPrintFrontPitchPrintWoopitchprint+2 more
REST Endpoints
/wp-json/pitchprint/v1/designs/wp-json/pitchprint/v1/products
Shortcode Output
<div class="pitchprint-product-designer"></div><div id="pitchprint_editor"></div><div class="pp-upload-area"></div>
FAQ

Frequently Asked Questions about PitchPrint