---
id: CVE-2026-82187
title: >-
  The Web to Print Online Designer WordPress plugin before 2.15.0 does not
  validate the type or extension of uploaded files, and hands the token
  protecting those uploads to any visitor who asks for it, allowing
  unauthenticated attackers to…
summary: >-
  The Web to Print Online Designer WordPress plugin before 2.15.0 does not
  validate the type or extension of uploaded files, and hands the token
  protecting those uploads to any visitor who asks for it, allowing
  unauthenticated attackers to…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-434
product: Web to Print Online Designer
affected:
  - web_to_print_online_designer >= 1.7.0 < 2.15.0
published: '2026-09-21'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T15:17:32.223'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82187'
references:
  - url: 'https://wpscan.com/vulnerability/d3e49486-6c08-41d5-86c9-3aaff670fc63/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-21T14:29:45.498251Z'
epss: 0.00545
epssPercentile: 0.43282
ingestedAt: '2026-09-21T06:32:37.147Z'
---

## Overview

The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on the server.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
