plugin

Wp File Upload Vulnerabilities

68 known security issues reported for the Wp File Upload WordPress plugin. Most recent disclosed Aug 5, 2026.

8 critical 6 high 18 medium

Running Wp File Upload on your site? Check whether your installed version is affected.

Scan your site free

Iptanus File Upload <= 5.1.7 - Unauthenticated SQL Injection

high

The Iptanus File Upload plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL quer...

CVSS:
7.5
Affected:
up to 5.1.7
Fixed in:
5.1.8
Disclosed:
Aug 5, 2026

CVE-2026-66447 on NVD →

File Upload <= 5.1.7 - Unauthenticated SQL Injection

high

The File Upload plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into...

CVSS:
7.5
Affected:
up to 5.1.7
Fixed in:
5.1.8
Disclosed:
Aug 3, 2026

CVE-2026-17044 on NVD →

WordPress File Upload [wp-file-upload] < 4.25.3 (closed)

unknown

[en] The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.25.2. This is due to missing or incorrect nonce validation on the 'wfu_file_details' function. This makes it possible for unauthenticated attackers to modify user data details associat...

Affected:
up to 4.25.3
Fixed in:
4.25.3
Disclosed:
Feb 25, 2025

CVE-2024-13494 on NVD →

WordPress File Upload <= 4.25.2 - Cross-Site Request Forgery in wfu_file_details

medium

The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.25.2. This is due to missing or incorrect nonce validation on the 'wfu_file_details' function. This makes it possible for unauthenticated attackers to modify user data details associated wi...

CVSS:
4.3
Affected:
up to 4.25.2
Fixed in:
4.25.3
Disclosed:
Feb 24, 2025

CVE-2024-13494 on NVD →

WordPress File Upload [wp-file-upload] < 4.24.14 (closed)

unknown

[en] The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie parameter. This makes it possible for unauthenticated attackers to execute code on the server.

Affected:
up to 4.24.14
Fixed in:
4.24.14
Disclosed:
Jan 8, 2025

CVE-2024-11635 on NVD →

WordPress File Upload [wp-file-upload] < 4.25.0 (closed)

unknown

[en] The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion in all versions up to, and including, 4.24.15 via the 'wfu_file_downloader.php' file. This is due to lack of proper sanitization of the 'source' parameter and allowing a user-defi...

Affected:
up to 4.25.0
Fixed in:
4.25.0
Disclosed:
Jan 8, 2025

CVE-2024-11613 on NVD →

WordPress File Upload <= 4.24.12 - Unuathenticated Remote Code Execution

critical

The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie parameter. This makes it possible for unauthenticated attackers to execute code on the server.

CVSS:
9.8
Affected:
up to 4.24.12
Fixed in:
4.24.14
Disclosed:
Jan 7, 2025

CVE-2024-11635 on NVD →

WordPress File Upload <= 4.24.15 - Unauthenticated Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion

critical

The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion in all versions up to, and including, 4.24.15 via the 'wfu_file_downloader.php' file. This is due to lack of proper sanitization of the 'source' parameter and allowing a user-defined d...

CVSS:
9.8
Affected:
up to 4.24.15
Fixed in:
4.25.0
Disclosed:
Jan 7, 2025

CVE-2024-11613 on NVD →

WordPress File Upload <= 4.24.13 - Unauthenticated Path Traversal to Arbitrary File Read in wfu_file_downloader.php

high

The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.13 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read files outside of the originally intended directory.

CVSS:
7.5
Affected:
up to 4.24.13
Fixed in:
4.24.14
Disclosed:
Jan 7, 2025

CVE-2024-9939 on NVD →

WordPress File Upload [wp-file-upload] < 4.25.0 (closed)

unknown

[en] The WordPress File Upload plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wfu_ajax_action_read_subfolders' function in all versions up to, and including, 4.24.15. This makes it possible for authenticated attackers, with Subscriber-level access and above,...

Affected:
up to 4.25.0
Fixed in:
4.25.0
Disclosed:
Jan 7, 2025

CVE-2024-12719 on NVD →

WordPress File Upload <= 4.24.15 - Missing Authorization to Authenticated (Subscriber+) Limited Path Traversal

medium

The WordPress File Upload plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wfu_ajax_action_read_subfolders' function in all versions up to, and including, 4.24.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to pe...

CVSS:
4.3
Affected:
up to 4.24.15
Fixed in:
4.25.0
Disclosed:
Jan 6, 2025

CVE-2024-12719 on NVD →

WordPress File Upload [wp-file-upload] < 4.24.8 (closed)

unknown

[en] Broken Access Control vulnerability in Nickolas Bossinas WordPress File Upload allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress File Upload: from n/a through 4.24.7.

Affected:
up to 4.24.8
Fixed in:
4.24.8
Disclosed:
Nov 1, 2024

CVE-2024-39639 on NVD →

WordPress File Upload [wp-file-upload] < 4.24.12 (closed)

unknown

[en] The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read or delete files outside of the originally intended directory. Successful exploitation requires the t...

Affected:
up to 4.24.12
Fixed in:
4.24.12
Disclosed:
Oct 12, 2024

CVE-2024-9047 on NVD →

WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php

critical

The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read or delete files outside of the originally intended directory. Successful exploitation requires the target...

CVSS:
9.8
Affected:
up to 4.24.11
Fixed in:
4.24.12
Disclosed:
Oct 11, 2024

CVE-2024-9047 on NVD →

WordPress File Upload [wp-file-upload] < 4.24.9 (closed)

unknown

[en] The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.24.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...

Affected:
up to 4.24.9
Fixed in:
4.24.9
Disclosed:
Aug 16, 2024

CVE-2024-7301 on NVD →

WordPress File Upload <= 4.24.8 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload

high

The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.24.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wil...

CVSS:
7.2
Affected:
up to 4.24.8
Fixed in:
4.24.9
Disclosed:
Aug 15, 2024

CVE-2024-7301 on NVD →

WordPress File Upload [wp-file-upload] < 4.24.8 (closed)

unknown

[en] The WordPress File Upload WordPress plugin before 4.24.8 does not properly sanitize and escape certain parameters, which could allow unauthenticated users to execute stored cross-site scripting (XSS) attacks.

Affected:
up to 4.24.8
Fixed in:
4.24.8
Disclosed:
Aug 7, 2024

CVE-2024-6494 on NVD →

WordPress File Upload [wp-file-upload] < 4.24.8 (closed)

unknown

[en] The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected:
up to 4.24.8
Fixed in:
4.24.8
Disclosed:
Aug 6, 2024

CVE-2024-6651 on NVD →

WordPress File Upload <= 4.24.7 - Missing Authorization

medium

The WordPress File Upload plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wfu_ajax_action_save_shortcode() function in versions up to, and including, 4.24.7. This makes it possible for authenticated attackers, with contributor-level access and above, to save shortcodes

CVSS:
5.4
Affected:
up to 4.24.7
Fixed in:
4.24.8
Disclosed:
Aug 1, 2024

CVE-2024-39639 on NVD →

WordPress File Upload <= 4.24.7 - Unauthenticated Stored Cross-Site Scripting

high

The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom text fileds in all versions up to, and including, 4.24.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that w...

CVSS:
7.2
Affected:
up to 4.24.7
Fixed in:
4.24.8
Disclosed:
Jul 16, 2024

CVE-2024-6494 on NVD →

WordPress File Upload <= 4.24.7 - Reflected Cross-Site Scripting

medium

The WordPress File Upload plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dir' parameter in all versions up to, and including, 4.24.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...

CVSS:
6.1
Affected:
up to 4.24.7
Fixed in:
4.24.8
Disclosed:
Jul 16, 2024

CVE-2024-6651 on NVD →

WordPress File Upload [wp-file-upload] < 4.24.8 (closed)

unknown

[en] The WordPress File Upload plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.24.7 via the 'uploadpath' parameter of the wordpress_file_upload shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload limited file...

Affected:
up to 4.24.8
Fixed in:
4.24.8
Disclosed:
Jul 16, 2024

CVE-2024-5852 on NVD →

WordPress File Upload <= 4.24.7 - Authenticated (Contributor+) Directory Traversal

medium

The WordPress File Upload plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.24.7 via the 'uploadpath' parameter of the wordpress_file_upload shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload limited files to...

CVSS:
4.3
Affected:
up to 4.24.7
Fixed in:
4.24.8
Disclosed:
Jul 15, 2024

CVE-2024-5852 on NVD →

WordPress File Upload [wp-file-upload] < 4.24.6 (closed)

unknown

[en] The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.24.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with con...

Affected:
up to 4.24.6
Fixed in:
4.24.6
Disclosed:
Apr 9, 2024

CVE-2024-2847 on NVD →

WordPress File Upload [wp-file-upload] < 2.4.4 (closed)

unknown

[en] A vulnerability has been found in wp-file-upload Plugin up to 2.4.3 on WordPress and classified as problematic. Affected by this vulnerability is the function wfu_ajax_action_callback of the file lib/wfu_ajaxactions.php. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading...

Affected:
up to 2.4.4
Fixed in:
2.4.4
Disclosed:
Mar 31, 2024

CVE-2014-125110 on NVD →

WordPress File Upload <= 4.24.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.24.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribu...

CVSS:
6.4
Affected:
up to 4.24.5
Fixed in:
4.24.6
Disclosed:
Mar 29, 2024

CVE-2024-2847 on NVD →

Wordpress File Upload 4.24.0 - Cross-Site Request Forgery

medium

The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.24.0. This is due to missing or incorrect nonce validation on the wfu_ajax_action_save_shortcode function. This makes it possible for unauthenticated attackers to save shortcodes via a forg...

CVSS:
4.3
Affected:
up to 4.24.0
Fixed in:
4.24.1
Disclosed:
Nov 14, 2023

WordPress File Upload [wp-file-upload] < 4.24.1 (closed)

unknown

The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.24.0. This is due to missing or incorrect nonce validation on the wfu_ajax_action_save_shortcode function. This makes it possible for unauthenticated attackers to save shortcodes via a forg...

Affected:
up to 4.24.1
Fixed in:
4.24.1
Disclosed:
Nov 14, 2023

WordPress File Upload [wp-file-upload] < 4.23.3 (closed)

unknown

[en] The WordPress File Upload WordPress plugin before 4.23.3 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks.

Affected:
up to 4.23.3
Fixed in:
4.23.3
Disclosed:
Oct 16, 2023

CVE-2023-4811 on NVD →

WordPress File Upload [wp-file-upload] < 4.23.3 (closed)

unknown

Update the WordPress File Upload plugin to the latest available version (at least 4.23.3). Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WordPress File Upload Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other...

Affected:
up to 4.23.3
Fixed in:
4.23.3
Disclosed:
Sep 14, 2023

Wordpress File Upload <= 4.23.2 - Authenticated(Administrator+) Stored Cross-Site Scripting

medium

The Wordpress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute in versions up to, and including, 4.23.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...

CVSS:
4.4
Affected:
up to 4.23.3
Fixed in:
4.23.3
Disclosed:
Sep 12, 2023

CVE-2023-4811 on NVD →

WordPress File Upload [wp-file-upload] < 4.23.3 (closed)

unknown

The Wordpress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute in versions up to, and including, 4.23.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...

Affected:
up to 4.23.3
Fixed in:
4.23.3
Disclosed:
Sep 12, 2023

WordPress File Upload [wp-file-upload] < 4.19.2 (closed)

unknown

[en] The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Path Traversal in versions up to, and including, 4.19.1 via the vulnerable parameter wfu_newpath. This allows administrator-level attackers to move files uploaded with the plugin (located in wp-content/uploads by defaul...

Affected:
up to 4.19.2
Fixed in:
4.19.2
Disclosed:
Jun 9, 2023

CVE-2023-2688 on NVD →

WordPress File Upload [wp-file-upload] < 4.19.2 (closed)

unknown

[en] The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.19.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...

Affected:
up to 4.19.2
Fixed in:
4.19.2
Disclosed:
Jun 9, 2023

CVE-2023-2767 on NVD →

WordPress File Upload / WordPress File Upload Pro <= 4.19.1 - Authenticated (Administrator+) Path Traversal

medium

The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Path Traversal in versions up to, and including, 4.19.1 via the vulnerable parameter wfu_newpath. This allows administrator-level attackers to move files uploaded with the plugin (located in wp-content/uploads by default) ou...

CVSS:
4.9
Affected:
up to 4.19.1
Fixed in:
4.19.2
Disclosed:
May 23, 2023

CVE-2023-2688 on NVD →

WordPress File Upload / WordPress File Upload Pro <= 4.19.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.19.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level...

CVSS:
4.4
Affected:
up to 4.19.1
Fixed in:
4.19.2
Disclosed:
May 23, 2023

CVE-2023-2767 on NVD →

WordPress File Upload [wp-file-upload] < 4.16.4 (closed)

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress WordPress File Upload plugin (versions <= 4.16.3). Update the WordPress WordPress File Upload plugin to the latest available version (at least 4.16.4).

Affected:
up to 4.16.4
Fixed in:
4.16.4
Disclosed:
May 16, 2022

WordPress File Upload <= 4.16.3 - Cross-Site Scripting

medium

The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.16.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
5.4
Affected:
up to 4.16.3
Fixed in:
4.16.4
Disclosed:
May 15, 2022

WordPress File Upload [wp-file-upload] < 4.16.4 (closed)

unknown

The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.16.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 4.16.4
Fixed in:
4.16.4
Disclosed:
May 15, 2022

WordPress File Upload [wp-file-upload] < 4.16.3 (closed)

unknown

[en] The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to perform path traversal via a shortcode argument, which can then be used to upload a PHP code disguised as an image inside the auto-loaded directory of the plugin, resulting in arbitrary code exec...

Affected:
up to 4.16.3
Fixed in:
4.16.3
Disclosed:
Mar 28, 2022

CVE-2021-24962 on NVD →

WordPress File Upload [wp-file-upload] < 4.16.3 (closed)

unknown

[en] The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 does not escape some of its shortcode argument, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

Affected:
up to 4.16.3
Fixed in:
4.16.3
Disclosed:
Mar 7, 2022

CVE-2021-24961 on NVD →

WordPress File Upload [wp-file-upload] < 4.16.3 (closed)

unknown

[en] The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allows users with a role as low as Contributor to configure the upload form in a way that allows uploading of SVG files, which could be then be used for Cross-Site Scripting attacks

Affected:
up to 4.16.3
Fixed in:
4.16.3
Disclosed:
Mar 7, 2022

CVE-2021-24960 on NVD →

WordPress File Upload / WordPress File Upload Pro <= 4.16.2 - Authenticated (Contributor+) Path Traversal

medium

The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to perform path traversal via a shortcode argument, which can then be used to upload a PHP code disguised as an image inside the auto-loaded directory of the plugin, resulting in arbitrary code execution...

CVSS:
6.5
Affected:
up to 4.16.2
Fixed in:
4.16.3
Disclosed:
Mar 1, 2022

CVE-2021-24962 on NVD →

WordPress File Upload <= 4.16.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Malicious SVG

medium

The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allows users with a role as low as Contributor to configure the upload form in a way that allows uploading of SVG files, which could be then be used for Cross-Site Scripting attacks

CVSS:
5.4
Affected:
up to 4.16.3
Fixed in:
4.16.3
Disclosed:
Feb 14, 2022

CVE-2021-24960 on NVD →

WordPress File Upload <= 4.16.2 - Authenticated Stored Cross-Site Scripting via Shortcode

medium

The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 does not escape some of its shortcode argument, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

CVSS:
5.4
Affected:
up to 4.16.3
Fixed in:
4.16.3
Disclosed:
Feb 14, 2022

CVE-2021-24961 on NVD →

WordPress File Upload <= 4.12.2 - Directory Traversal to Remote Code Execution

critical

An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call.

CVSS:
9.8
Affected:
up to 4.12.2
Fixed in:
4.13.0
Disclosed:
Mar 13, 2020

CVE-2020-10564 on NVD →

WordPress File Upload [wp-file-upload] < 4.13.0 (closed)

unknown

[en] An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call.

Affected:
up to 4.13.0
Fixed in:
4.13.0
Disclosed:
Mar 13, 2020

CVE-2020-10564 on NVD →

WordPress File Upload [wp-file-upload] < 3.0.0 (closed)

unknown

[en] The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess files.

Affected:
up to 3.0.0
Fixed in:
3.0.0
Disclosed:
Aug 22, 2019

CVE-2015-9340 on NVD →

WordPress File Upload [wp-file-upload] < 2.7.1 (closed)

unknown

[en] The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.

Affected:
up to 2.7.1
Fixed in:
2.7.1
Disclosed:
Aug 22, 2019

CVE-2015-9339 on NVD →

WordPress File Upload [wp-file-upload] < 2.5.0 (closed)

unknown

[en] The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.

Affected:
up to 2.5.0
Fixed in:
2.5.0
Disclosed:
Aug 22, 2019

CVE-2015-9338 on NVD →

WordPress File Upload [wp-file-upload] < 3.4.1 (closed)

unknown

[en] The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.

Affected:
up to 3.4.1
Fixed in:
3.4.1
Disclosed:
Aug 22, 2019

CVE-2015-9341 on NVD →

WordPress File Upload [wp-file-upload] < 4.3.4 (closed)

unknown

[en] The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS.

Affected:
up to 4.3.4
Fixed in:
4.3.4
Disclosed:
Apr 7, 2018

CVE-2018-9844 on NVD →

WordPress File Upload <= 4.3.3 - Stored Cross-Site Scripting

medium

The WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS.

CVSS:
6.1
Affected:
up to 4.3.4
Fixed in:
4.3.4
Disclosed:
Apr 6, 2018

CVE-2018-9844 on NVD →

WordPress File Upload [wp-file-upload] < 4.3.3 (closed)

unknown

[en] The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.

Affected:
up to 4.3.3
Fixed in:
4.3.3
Disclosed:
Apr 1, 2018

CVE-2018-9172 on NVD →

WordPress File Upload <= 4.3.2 - Cross-Site Scripting via Shortcodes

medium

The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.

CVSS:
4.1
Affected:
up to 4.3.3
Fixed in:
4.3.3
Disclosed:
Mar 31, 2018

CVE-2018-9172 on NVD →

WordPress File Upload < 3.9.0 - Arbitrary File Upload

critical

The WordPress File Upload plugin is vulnerable to arbitrary file uploads due to insufficient file type validation in versions up to, and including, 3.8.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

CVSS:
9.8
Affected:
up to 3.9.0
Fixed in:
3.9.0
Disclosed:
Jun 23, 2016

WordPress File Upload [wp-file-upload] < 3.9.0 (closed)

unknown

The WordPress File Upload plugin is vulnerable to arbitrary file uploads due to insufficient file type validation in versions up to, and including, 3.8.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

Affected:
up to 3.9.0
Fixed in:
3.9.0
Disclosed:
Jun 23, 2016

WordPress File Upload <= 3.4.0 - Arbitrary File Upload

critical

The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.

CVSS:
9.8
Affected:
up to 3.4.1
Fixed in:
3.4.1
Disclosed:
Oct 29, 2015

CVE-2015-9341 on NVD →

WordPress File Upload [wp-file-upload] < 3.4.1 (closed)

unknown

Because of this unauthenticated malicious file upload vulnerability, attackers can upload malicious payloads. Upgrade the plugin.

Affected:
up to 3.4.1
Fixed in:
3.4.1
Disclosed:
Oct 29, 2015

WordPress File Upload < 3.0.0 - Arbitrary File Upload

critical

The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess files.

CVSS:
9.8
Affected:
up to 3.0.0
Fixed in:
3.0.0
Disclosed:
Jul 2, 2015

CVE-2015-9340 on NVD →

WordPress File Upload < 2.7.1 - Arbitrary File Upload

high

The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.

CVSS:
8.2
Affected:
up to 2.7.1
Fixed in:
2.7.1
Disclosed:
May 9, 2015

CVE-2015-9339 on NVD →

WordPress File Upload <= 2.4.6 - Arbitrary File Upload

critical

The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.

CVSS:
9.8
Affected:
up to 2.4.6
Fixed in:
2.5.0
Disclosed:
Jan 23, 2015

CVE-2015-9338 on NVD →

WordPress File Upload <= 2.4.3 - Reflected Cross-Site Scripting

medium

The WordPress File Upload plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can su...

CVSS:
6.1
Affected:
up to 2.4.3
Fixed in:
2.4.4
Disclosed:
Aug 20, 2014

CVE-2014-125110 on NVD →

WordPress File Upload [wp-file-upload] < 2.4.2 (closed)

unknown

[en] Cross-site request forgery (CSRF) vulnerability in the WordPress File Upload plugin (wp-file-upload) before 2.4.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors. NOTE: some of these details are obtained from thi...

Affected:
up to 2.4.2
Fixed in:
2.4.2
Disclosed:
Aug 12, 2014

CVE-2014-5199 on NVD →

WordPress File Upload < 2.4.2 - Cross-Site Request Forgery

medium

Cross-site request forgery (CSRF) vulnerability in the WordPress File Upload plugin (wp-file-upload) before 2.4.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors.

CVSS:
6.3
Affected:
up to 2.4.2
Fixed in:
2.4.2
Disclosed:
Aug 8, 2014

CVE-2014-5199 on NVD →

WordPress File Upload [wp-file-upload] < 4.24.1 (closed)

unknown

The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.24.0. This is due to missing or incorrect nonce validation on the wfu_ajax_action_save_shortcode function. This makes it possible for unauthenticated attackers to save shortcodes via a forg...

Affected:
up to 4.24.1
Fixed in:
4.24.1

WordPress File Upload [wp-file-upload] < 4.24.14 (closed)

unknown
Affected:
up to 4.24.14
Fixed in:
4.24.14

CVE-2024-9939 on NVD →

WordPress File Upload [wp-file-upload] < 3.9.0 (closed)

unknown

The WordPress File Upload WordPress plugin was affected by an Insufficient File Extension Blacklisting security vulnerability.

Affected:
up to 3.9.0
Fixed in:
3.9.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database