Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-82187: Web to Print Online Designer lets anyone upload files

CVE-2026-82187 · published today
Summary

The Web to Print Online Designer plugin for WordPress does not check what kind of files are uploaded and gives out the upload token to anyone who asks. This means an unauthenticated person could upload malicious files, including code that runs on your server. Update the plugin to version 2.15.0 or later, or remove it if you cannot apply the update.

What to do
  • Update unknown web to print online designer to version 2.15.0 or later.
Affected software
VendorProductAffected versions
unknown web to print online designer < 2.15.0
Original advisory text
WooCommerce Online Product Designer 1.7.0 - < 2.15.0 - Unauthenticated Arbitrary File Upload
The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on the server.
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-434Unrestricted File Upload
Timeline
Published21 Sep 2026
Updated21 Sep 2026
First seen21 Sep 2026
Sources
CVE-2026-82187 · MITRE
Track software like this
Free during beta