plugin

Work The Flow File Upload Vulnerabilities

11 known security issues reported for the Work The Flow File Upload WordPress plugin. Most recent disclosed Jul 19, 2025.

2 critical

Running Work The Flow File Upload on your site? Check whether your installed version is affected.

Scan your site free

Work The Flow File Upload [work-the-flow-file-upload] < 2.5.3 (closed)

unknown

[en] The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server and test files in versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affecte...

Affected:
up to 2.5.3
Fixed in:
2.5.3
Disclosed:
Jul 19, 2025

CVE-2015-10138 on NVD →

Work The Flow File Upload [work-the-flow-file-upload] < 2.5.3 (closed)

unknown

This vulnerability allows an attacker to upload arbitrary PHP code and execute it. Update the plugin.

Affected:
up to 2.5.3
Fixed in:
2.5.3
Disclosed:
Apr 21, 2015

Work The Flow File Upload [work-the-flow-file-upload] < 2.5.3 (closed)

unknown

WordPress Work The Flow File Upload plugin is prone to an arbitrary file upload vulnerability. It allows an attacker to upload arbitrary files to the affected computer. Upgrade the plugin.

Affected:
up to 2.5.3
Fixed in:
2.5.3
Disclosed:
Apr 5, 2015

Work The Flow File Upload <= 2.5.2 - Arbitrary File Upload

critical

The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server and test files in versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sit...

CVSS:
9.8
Affected:
up to 2.5.2
Fixed in:
2.5.3
Disclosed:
Mar 14, 2015

CVE-2015-10138 on NVD →

Work The Flow File Upload [work-the-flow-file-upload] < 2.5.3 (closed)

unknown

The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server and test files in versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sit...

Affected:
up to 2.5.3
Fixed in:
2.5.3
Disclosed:
Mar 14, 2015

Work The Flow <= 2.3.1 - Arbitrary File Upload

critical

The Work The Flow plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the accept_file_types function in versions up to, and including, 2.3.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote...

CVSS:
9.8
Affected:
up to 2.3.1
Fixed in:
2.3.2
Disclosed:
Oct 12, 2014

Work The Flow File Upload [work-the-flow-file-upload] < 2.3.2 (closed)

unknown

The Work The Flow plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the accept_file_types function in versions up to, and including, 2.3.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote...

Affected:
up to 2.3.2
Fixed in:
2.3.2
Disclosed:
Oct 12, 2014

Work The Flow File Upload [work-the-flow-file-upload] <= 1.2.1 (closed)

unknown

Work The Flow plugin is prone to an arbitrary file upload vulnerability that submit an image file via the wtf upload panel and intercept the POST request to /wp-admin/admin-ajax.php. Edit the data from the control "accept_file_types".

Affected:
up to 1.2.1
Fixed in:
1.2.1
Disclosed:
Apr 24, 2014

Work The Flow File Upload [work-the-flow-file-upload] < 2.5.3 (closed)

unknown

PoC: curl -k -X POST -F &quot;action=upload&quot; -F &quot;[email&nbsp;protected]/backdoor.php&quot; http://VICTIM/wp-content/plugins/work-the-flow-file-upload/public/assets/jQuery-File-Upload-9.5.0/server/php/index.php Backdoor Location: http://VICTIM/wp-content/plugins/work-the-flow-file-upload/public/assets...

Affected:
up to 2.5.3
Fixed in:
2.5.3

Work The Flow File Upload [work-the-flow-file-upload] < 2.3.2 (closed)

unknown

The work-the-flow-file-upload WordPress plugin was affected by a Shell Upload security vulnerability.

Affected:
up to 2.3.2
Fixed in:
2.3.2

Work The Flow File Upload [work-the-flow-file-upload] < 2.4 (closed)

unknown

See https://github.com/wpscanteam/wpscan/issues/673#issuecomment-53972233

Affected:
up to 2.4
Fixed in:
2.4

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database