plugin

Uploader Vulnerabilities

8 known security issues reported for the Uploader WordPress plugin. Most recent disclosed Aug 1, 2014.

1 critical 1 medium

Running Uploader on your site? Check whether your installed version is affected.

Scan your site free

Uploader <= 1.0.4 - Arbitrary File Upload

critical

The Uploader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '/uploadify/uploadify.php' file in versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote...

CVSS:
9.8
Affected:
up to 1.0.4
Fix:
No patched version reported
Disclosed:
Aug 1, 2014

Uploader <= 1.0.4 - Multiple Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) notify or (2) blog parameter.

CVSS:
6.1
Affected:
up to 1.0.4
Fix:
No patched version reported
Disclosed:
Aug 1, 2014

CVE-2013-2287 on NVD →

Uploader [uploader] <= 1.0.4 (unfixed + closed)

unknown

The Uploader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '/uploadify/uploadify.php' file in versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote...

Affected:
up to 1.0.4
Fix:
No patched version reported
Disclosed:
Aug 1, 2014

Uploader [uploader] <= 1.0.4 (closed)

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) notify or (2) blog parameter.

Affected:
up to 1.0.4
Fixed in:
1.0.4
Disclosed:
Apr 4, 2014

CVE-2013-2287 on NVD →

Uploader [uploader] < 1.0.5 (closed)

unknown

WordPress Uploader plugin is prone to an arbitrary file upload vulnerability because of failure of adequately validate files before uploading them. This vulnerability allows an attacker to upload arbitrary files to the affected computer. Update the plugin.

Affected:
up to 1.0.5
Fixed in:
1.0.5
Disclosed:
Jan 3, 2013

Uploader [uploader] < 1.0.1 (closed)

unknown

This WordPress Uploader plugin's "num" parameter is prone to a cross-site scripting vulnerability. It fails to properly clean up user-supplied input. An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-based authentica...

Affected:
up to 1.0.1
Fixed in:
1.0.1
Disclosed:
Jan 24, 2011

Uploader [uploader] <= 1.0.4 (unfixed + closed)

unknown
Affected:
up to 1.0.4
Fix:
No patched version reported

Uploader [uploader] <= 1.0.4 (unfixed + closed)

unknown
Affected:
up to 1.0.4
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database