CRITICAL 9.8 CVE-2026-82187 Published 21 Sept 2026

WordPress Web to Print Online Designer Plugin Arbitrary File Upload RCE

Worried this affects your website?

The Web to Print Online Designer WordPress plugin before 2.15.0 contains an arbitrary file upload vulnerability.

The plugin does not validate the type or extension of uploaded files, and it hands the token protecting those uploads to any visitor who asks for it.

  • Affected versions: before 2.15.0
  • Attackers: unauthenticated
  • Impact: arbitrary file upload, including PHP files, leading to remote code execution on the server.

Reference: CVE-2026-82187 on NVD

← Back to Security News