CVE-2026-82187
Received Received - Intake

Arbitrary File Upload in Web to Print Online Designer WordPress Plugin

Vulnerability report for CVE-2026-82187, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-21

Last updated on: 2026-09-21

Assigner: WPScan

Description

The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on the server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-21
Last Modified
2026-09-21
Generated
2026-09-21
AI Q&A
2026-09-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated arbitrary file upload flaw in the Web to Print Online Designer WordPress plugin versions before 2.15.0. The plugin does not validate file types or extensions during uploads and exposes the token protecting these uploads to any visitor. This allows attackers to upload arbitrary files, including PHP files, which can then be executed on the server.

Detection Guidance
  • Check the installed version of the Web to Print Online Designer plugin. If it is below 2.15.0, the system is vulnerable.
  • Look for unexpected or unauthorized files in the uploads directory, especially PHP files.
  • Monitor server logs for unusual upload activity or requests to the token endpoint.
Impact Analysis

Unauthenticated attackers can exploit this vulnerability to upload malicious files to your server. These files could include PHP scripts that allow attackers to execute arbitrary code, potentially leading to full server compromise, data theft, or further attacks on your system.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements under GDPR and HIPAA. It may result in data breaches, unauthorized data access, or loss of data integrity, all of which are critical compliance violations.

Mitigation Strategies
  • Update the Web to Print Online Designer plugin to version 2.15.0 or later immediately.
  • Remove any unauthorized or suspicious files from the uploads directory.
  • Restrict write permissions on the uploads directory to prevent unauthorized file uploads.
  • Monitor network traffic for signs of exploitation or unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82187. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart