← Back to search

CVE-2026-82187

9.8 CRITICAL

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
The flaw allows unauthenticated attackers to upload arbitrary files, including PHP files, to execute code on the server, due to lack of file type and extension validation.
Exploitability
Exploitation is relatively easy as it requires no authentication and the attacker can upload PHP files to execute arbitrary code.
Blast radius
If exploited, the impact could be severe, as the attacker could gain full control over the server, leading to data theft, service disruption, or further attacks.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to version 2.15.0 or later.
rceuploadwebphpunauth

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on the server.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-434

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.