CVE-2026-82187
9.8 CRITICALPublished 2026-09-21 · Updated 2026-09-21
AI risk analysis
- Summary
- The flaw allows unauthenticated attackers to upload arbitrary files, including PHP files, to execute code on the server, due to lack of file type and extension validation.
- Exploitability
- Exploitation is relatively easy as it requires no authentication and the attacker can upload PHP files to execute arbitrary code.
- Blast radius
- If exploited, the impact could be severe, as the attacker could gain full control over the server, leading to data theft, service disruption, or further attacks.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to version 2.15.0 or later.
rceuploadwebphpunauth
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on the server.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-434
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-70356PoC
- CRITICALCVE-2026-93352PoC
- HIGHCVE-2026-94104PoC
- HIGHCVE-2026-12264
- CRITICALCVE-2026-13249
- CRITICALCVE-2026-14175
- HIGHCVE-2026-14553
- CRITICALCVE-2026-16618
Related by shared AI tags and CWE weakness class. Browse the full archive.