MaxUpload <= 1.4.0 - Unauthenticated Arbitrary File Upload via 'resumableFilename' Parameter
highThe MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.4.0 via the handle_upload function. This is due to a filename-validation mismatch in the handle_upload function where extension and MIME checks are app...
- CVSS:
- 8.8
- Affected:
- up to 1.4.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 14, 2026