OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-82187

CRITICAL · CVSS 9.8 EPSS 0.55%

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The Web to Print Online Designer plugin for WordPress prior to version 2.15.0 is vulnerable due to inadequate validation of uploaded file types, allowing unauthenticated attackers to upload arbitrary files, including executable PHP scripts. This critical vulnerability can lead to remote code execution on the server, posing significant risks to the integrity and security of the affected WordPress installations. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-82187
Severity
CRITICAL
CVSS
9.8
EPSS
0.55%
WordPress

Original NVD Description

The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on the server.