PT-2026-96041 · WordPress · Web To Print Online Designer

·

CVE-2026-82187

·

Published

2026-09-21

·

Updated

2026-09-22

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Web to Print Online Designer WordPress plugin versions prior to 2.15.0
Description Insufficient validation of uploaded file types and extensions allows unauthenticated attackers to upload arbitrary files, including PHP scripts. Additionally, the plugin exposes the token protecting these uploads to any visitor, enabling remote code execution on the server.
Recommendations Update the plugin to version 2.15.0 or later.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82187

Affected Products

Web To Print Online Designer