CVE-2026-82187
Last modified
CVE-2026-82187 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on the server.. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on the server.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | Web to Print Online Designer | >= 1.7.0, < 2.15.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-82187?
How severe is CVE-2026-82187?
How do I fix CVE-2026-82187?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-82181Medical Practice Management System developed by Le-yan has a…5.5
- CVE-2026-82182The WPvivid — Backup, Migration & Staging WordPress plugin b…4.1
- CVE-2026-82183The OAuth Single Sign On WordPress plugin before 7.0.1 does…8.1
- CVE-2026-82184The WPLP Cookie Consent WordPress plugin before 4.4.2 does …5.3
- CVE-2026-82185The WPLP Cookie Consent WordPress plugin before 4.4.2 does …4.3
- CVE-2026-82186The WPLP Cookie Consent WordPress plugin before 4.4.2 does …4.1
- CVE-2026-82189Joomla Extension - j2commerce.com - Any order can be marked …8.7
- CVE-2026-8219A security vulnerability has been detected in Devs Palace ER…2.4
- CVE-2026-82190Joomla Extension - j2commerce.com - Predictable/forgeable or…6.3
- CVE-2026-82191Joomla Extension - j2commerce.com - Unescaped request data r…5.3
- CVE-2026-82193The WPvivid — Backup, Migration & Staging WordPress plugin b…5.5
- CVE-2026-82194The WPvivid — Backup, Migration & Staging WordPress plugin b…5.5
Are you affected by CVE-2026-82187?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
