{"id":"CVE-2026-82187","published":"2026-09-21T07:16:53.317","lastModified":"2026-09-21T15:17:32.223","description":"The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on the server.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-434"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/d3e49486-6c08-41d5-86c9-3aaff670fc63/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated attackers to upload arbitrary files, including PHP files, to execute code on the server, due to lack of file type and extension validation.","exploitability":"Exploitation is relatively easy as it requires no authentication and the attacker can upload PHP files to execute arbitrary code.","blast_radius":"If exploited, the impact could be severe, as the attacker could gain full control over the server, leading to data theft, service disruption, or further attacks.","remediation":"Upgrade to version 2.15.0 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","upload","web","php","unauth"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T09:00:05.210Z"}}