Impact
The Web to Print Online Designer plugin for WordPress lacks validation of file type or extension when files are uploaded. Unauthenticated users can also retrieve the upload token that is meant to protect the upload path. This combination allows an attacker to upload any file type, including PHP scripts, and execute code on the server, compromising confidentiality, integrity, and availability of the web application and underlying server.
Affected Systems
The vulnerability affects the Web to Print Online Designer WordPress plugin, versions prior to 2.15.0, including the WooCommerce Online Product Designer 1.7.0 release. Any WordPress site that has this plugin installed and is running a version older than 2.15.0 is potentially impacted.
Risk and Exploitability
The CVSS score is 9.8, the EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. The threat vector is remote via the web interface: any internet‑connected user can trigger file uploads without authentication. The lack of file type checks and the exposure of the upload token make exploitation straightforward, resulting in remote code execution once a malicious script is uploaded and accessed.
OpenCVE Enrichment