CyberRota Analysis
AI-GeneratedThe Web to Print Online Designer plugin for WordPress prior to version 2.15.0 is vulnerable due to inadequate validation of uploaded file types, allowing unauthenticated attackers to upload arbitrary files, including executable PHP scripts. This critical vulnerability can lead to remote code execution on the server, posing significant risks to the integrity and security of the affected WordPress installations. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential exploitation.
Original NVD Description
The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on the server.