Junglewise Threat Intelligence

CVE-2026-82187: Web to Print Online Designer arbitrary file upload

CVE-2026-82187 · Severity: critical · CVSS 9.8 · Published 2026-09-21

Vendors: WooCommerce.

Executive brief

The Web to Print Online Designer WordPress plugin is a tool that allows websites to enable customers to design and customize products online before purchase. The plugin fails to validate uploaded files and exposes security tokens to anyone, permitting unauthenticated attackers to upload malicious files including PHP scripts and execute arbitrary code on the web server, potentially leading to complete server compromise.

Technical details

The vulnerability exists in the file upload handler which lacks both file type/extension validation and proper token authentication. An unauthenticated attacker can request the upload token without authentication and use it to upload arbitrary files, including executable PHP code. Once uploaded, the attacker can access and execute the PHP file through the web server, achieving remote code execution with the privileges of the web server process.

Affected products

  • WooCommerce Online Product Designer 1.7.0 to 2.14.x

Timeline

  • 2026-09-19: disclosed
  • 2026-09-21: patched: Fixed in version 2.15.0

References