Iptanus File Upload <= 5.1.7 - Unauthenticated SQL Injection
high
The Iptanus File Upload plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL quer...
- CVSS:
- 7.5
- Affected:
- up to 5.1.7
- Fixed in:
- 5.1.8
- Disclosed:
- Aug 5, 2026
CVE-2026-66447 on NVD →
File Upload <= 5.1.7 - Unauthenticated SQL Injection
high
The File Upload plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into...
- CVSS:
- 7.5
- Affected:
- up to 5.1.7
- Fixed in:
- 5.1.8
- Disclosed:
- Aug 3, 2026
CVE-2026-17044 on NVD →
WordPress File Upload [wp-file-upload] < 4.25.3 (closed)
unknown
[en] The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.25.2. This is due to missing or incorrect nonce validation on the 'wfu_file_details' function. This makes it possible for unauthenticated attackers to modify user data details associat...
- Affected:
- up to 4.25.3
- Fixed in:
- 4.25.3
- Disclosed:
- Feb 25, 2025
CVE-2024-13494 on NVD →
WordPress File Upload <= 4.25.2 - Cross-Site Request Forgery in wfu_file_details
medium
The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.25.2. This is due to missing or incorrect nonce validation on the 'wfu_file_details' function. This makes it possible for unauthenticated attackers to modify user data details associated wi...
- CVSS:
- 4.3
- Affected:
- up to 4.25.2
- Fixed in:
- 4.25.3
- Disclosed:
- Feb 24, 2025
CVE-2024-13494 on NVD →
WordPress File Upload [wp-file-upload] < 4.24.14 (closed)
unknown
[en] The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie parameter. This makes it possible for unauthenticated attackers to execute code on the server.
- Affected:
- up to 4.24.14
- Fixed in:
- 4.24.14
- Disclosed:
- Jan 8, 2025
CVE-2024-11635 on NVD →
WordPress File Upload [wp-file-upload] < 4.25.0 (closed)
unknown
[en] The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion in all versions up to, and including, 4.24.15 via the 'wfu_file_downloader.php' file. This is due to lack of proper sanitization of the 'source' parameter and allowing a user-defi...
- Affected:
- up to 4.25.0
- Fixed in:
- 4.25.0
- Disclosed:
- Jan 8, 2025
CVE-2024-11613 on NVD →
WordPress File Upload <= 4.24.12 - Unuathenticated Remote Code Execution
critical
The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie parameter. This makes it possible for unauthenticated attackers to execute code on the server.
- CVSS:
- 9.8
- Affected:
- up to 4.24.12
- Fixed in:
- 4.24.14
- Disclosed:
- Jan 7, 2025
CVE-2024-11635 on NVD →
WordPress File Upload <= 4.24.15 - Unauthenticated Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion
critical
The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion in all versions up to, and including, 4.24.15 via the 'wfu_file_downloader.php' file. This is due to lack of proper sanitization of the 'source' parameter and allowing a user-defined d...
- CVSS:
- 9.8
- Affected:
- up to 4.24.15
- Fixed in:
- 4.25.0
- Disclosed:
- Jan 7, 2025
CVE-2024-11613 on NVD →
WordPress File Upload <= 4.24.13 - Unauthenticated Path Traversal to Arbitrary File Read in wfu_file_downloader.php
high
The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.13 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read files outside of the originally intended directory.
- CVSS:
- 7.5
- Affected:
- up to 4.24.13
- Fixed in:
- 4.24.14
- Disclosed:
- Jan 7, 2025
CVE-2024-9939 on NVD →
WordPress File Upload [wp-file-upload] < 4.25.0 (closed)
unknown
[en] The WordPress File Upload plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wfu_ajax_action_read_subfolders' function in all versions up to, and including, 4.24.15. This makes it possible for authenticated attackers, with Subscriber-level access and above,...
- Affected:
- up to 4.25.0
- Fixed in:
- 4.25.0
- Disclosed:
- Jan 7, 2025
CVE-2024-12719 on NVD →
WordPress File Upload <= 4.24.15 - Missing Authorization to Authenticated (Subscriber+) Limited Path Traversal
medium
The WordPress File Upload plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wfu_ajax_action_read_subfolders' function in all versions up to, and including, 4.24.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to pe...
- CVSS:
- 4.3
- Affected:
- up to 4.24.15
- Fixed in:
- 4.25.0
- Disclosed:
- Jan 6, 2025
CVE-2024-12719 on NVD →
WordPress File Upload [wp-file-upload] < 4.24.8 (closed)
unknown
[en] Broken Access Control vulnerability in Nickolas Bossinas WordPress File Upload allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress File Upload: from n/a through 4.24.7.
- Affected:
- up to 4.24.8
- Fixed in:
- 4.24.8
- Disclosed:
- Nov 1, 2024
CVE-2024-39639 on NVD →
WordPress File Upload [wp-file-upload] < 4.24.12 (closed)
unknown
[en] The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read or delete files outside of the originally intended directory. Successful exploitation requires the t...
- Affected:
- up to 4.24.12
- Fixed in:
- 4.24.12
- Disclosed:
- Oct 12, 2024
CVE-2024-9047 on NVD →
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
critical
The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read or delete files outside of the originally intended directory. Successful exploitation requires the target...
- CVSS:
- 9.8
- Affected:
- up to 4.24.11
- Fixed in:
- 4.24.12
- Disclosed:
- Oct 11, 2024
CVE-2024-9047 on NVD →
WordPress File Upload [wp-file-upload] < 4.24.9 (closed)
unknown
[en] The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.24.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...
- Affected:
- up to 4.24.9
- Fixed in:
- 4.24.9
- Disclosed:
- Aug 16, 2024
CVE-2024-7301 on NVD →
WordPress File Upload <= 4.24.8 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload
high
The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.24.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wil...
- CVSS:
- 7.2
- Affected:
- up to 4.24.8
- Fixed in:
- 4.24.9
- Disclosed:
- Aug 15, 2024
CVE-2024-7301 on NVD →
WordPress File Upload [wp-file-upload] < 4.24.8 (closed)
unknown
[en] The WordPress File Upload WordPress plugin before 4.24.8 does not properly sanitize and escape certain parameters, which could allow unauthenticated users to execute stored cross-site scripting (XSS) attacks.
- Affected:
- up to 4.24.8
- Fixed in:
- 4.24.8
- Disclosed:
- Aug 7, 2024
CVE-2024-6494 on NVD →
WordPress File Upload [wp-file-upload] < 4.24.8 (closed)
unknown
[en] The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 4.24.8
- Fixed in:
- 4.24.8
- Disclosed:
- Aug 6, 2024
CVE-2024-6651 on NVD →
WordPress File Upload <= 4.24.7 - Missing Authorization
medium
The WordPress File Upload plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wfu_ajax_action_save_shortcode() function in versions up to, and including, 4.24.7. This makes it possible for authenticated attackers, with contributor-level access and above, to save shortcodes
- CVSS:
- 5.4
- Affected:
- up to 4.24.7
- Fixed in:
- 4.24.8
- Disclosed:
- Aug 1, 2024
CVE-2024-39639 on NVD →
WordPress File Upload <= 4.24.7 - Unauthenticated Stored Cross-Site Scripting
high
The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom text fileds in all versions up to, and including, 4.24.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that w...
- CVSS:
- 7.2
- Affected:
- up to 4.24.7
- Fixed in:
- 4.24.8
- Disclosed:
- Jul 16, 2024
CVE-2024-6494 on NVD →
WordPress File Upload <= 4.24.7 - Reflected Cross-Site Scripting
medium
The WordPress File Upload plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dir' parameter in all versions up to, and including, 4.24.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...
- CVSS:
- 6.1
- Affected:
- up to 4.24.7
- Fixed in:
- 4.24.8
- Disclosed:
- Jul 16, 2024
CVE-2024-6651 on NVD →
WordPress File Upload [wp-file-upload] < 4.24.8 (closed)
unknown
[en] The WordPress File Upload plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.24.7 via the 'uploadpath' parameter of the wordpress_file_upload shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload limited file...
- Affected:
- up to 4.24.8
- Fixed in:
- 4.24.8
- Disclosed:
- Jul 16, 2024
CVE-2024-5852 on NVD →
WordPress File Upload <= 4.24.7 - Authenticated (Contributor+) Directory Traversal
medium
The WordPress File Upload plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.24.7 via the 'uploadpath' parameter of the wordpress_file_upload shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload limited files to...
- CVSS:
- 4.3
- Affected:
- up to 4.24.7
- Fixed in:
- 4.24.8
- Disclosed:
- Jul 15, 2024
CVE-2024-5852 on NVD →
WordPress File Upload [wp-file-upload] < 4.24.6 (closed)
unknown
[en] The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.24.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with con...
- Affected:
- up to 4.24.6
- Fixed in:
- 4.24.6
- Disclosed:
- Apr 9, 2024
CVE-2024-2847 on NVD →
WordPress File Upload [wp-file-upload] < 2.4.4 (closed)
unknown
[en] A vulnerability has been found in wp-file-upload Plugin up to 2.4.3 on WordPress and classified as problematic. Affected by this vulnerability is the function wfu_ajax_action_callback of the file lib/wfu_ajaxactions.php. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading...
- Affected:
- up to 2.4.4
- Fixed in:
- 2.4.4
- Disclosed:
- Mar 31, 2024
CVE-2014-125110 on NVD →
WordPress File Upload <= 4.24.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.24.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribu...
- CVSS:
- 6.4
- Affected:
- up to 4.24.5
- Fixed in:
- 4.24.6
- Disclosed:
- Mar 29, 2024
CVE-2024-2847 on NVD →
Wordpress File Upload 4.24.0 - Cross-Site Request Forgery
medium
The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.24.0. This is due to missing or incorrect nonce validation on the wfu_ajax_action_save_shortcode function. This makes it possible for unauthenticated attackers to save shortcodes via a forg...
- CVSS:
- 4.3
- Affected:
- up to 4.24.0
- Fixed in:
- 4.24.1
- Disclosed:
- Nov 14, 2023
WordPress File Upload [wp-file-upload] < 4.24.1 (closed)
unknown
The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.24.0. This is due to missing or incorrect nonce validation on the wfu_ajax_action_save_shortcode function. This makes it possible for unauthenticated attackers to save shortcodes via a forg...
- Affected:
- up to 4.24.1
- Fixed in:
- 4.24.1
- Disclosed:
- Nov 14, 2023
WordPress File Upload [wp-file-upload] < 4.23.3 (closed)
unknown
[en] The WordPress File Upload WordPress plugin before 4.23.3 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks.
- Affected:
- up to 4.23.3
- Fixed in:
- 4.23.3
- Disclosed:
- Oct 16, 2023
CVE-2023-4811 on NVD →
WordPress File Upload [wp-file-upload] < 4.23.3 (closed)
unknown
Update the WordPress File Upload plugin to the latest available version (at least 4.23.3).
Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WordPress File Upload Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other...
- Affected:
- up to 4.23.3
- Fixed in:
- 4.23.3
- Disclosed:
- Sep 14, 2023
Wordpress File Upload <= 4.23.2 - Authenticated(Administrator+) Stored Cross-Site Scripting
medium
The Wordpress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute in versions up to, and including, 4.23.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...
- CVSS:
- 4.4
- Affected:
- up to 4.23.3
- Fixed in:
- 4.23.3
- Disclosed:
- Sep 12, 2023
CVE-2023-4811 on NVD →
WordPress File Upload [wp-file-upload] < 4.23.3 (closed)
unknown
The Wordpress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute in versions up to, and including, 4.23.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...
- Affected:
- up to 4.23.3
- Fixed in:
- 4.23.3
- Disclosed:
- Sep 12, 2023
WordPress File Upload [wp-file-upload] < 4.19.2 (closed)
unknown
[en] The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Path Traversal in versions up to, and including, 4.19.1 via the vulnerable parameter wfu_newpath. This allows administrator-level attackers to move files uploaded with the plugin (located in wp-content/uploads by defaul...
- Affected:
- up to 4.19.2
- Fixed in:
- 4.19.2
- Disclosed:
- Jun 9, 2023
CVE-2023-2688 on NVD →
WordPress File Upload [wp-file-upload] < 4.19.2 (closed)
unknown
[en] The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.19.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...
- Affected:
- up to 4.19.2
- Fixed in:
- 4.19.2
- Disclosed:
- Jun 9, 2023
CVE-2023-2767 on NVD →
WordPress File Upload / WordPress File Upload Pro <= 4.19.1 - Authenticated (Administrator+) Path Traversal
medium
The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Path Traversal in versions up to, and including, 4.19.1 via the vulnerable parameter wfu_newpath. This allows administrator-level attackers to move files uploaded with the plugin (located in wp-content/uploads by default) ou...
- CVSS:
- 4.9
- Affected:
- up to 4.19.1
- Fixed in:
- 4.19.2
- Disclosed:
- May 23, 2023
CVE-2023-2688 on NVD →
WordPress File Upload / WordPress File Upload Pro <= 4.19.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.19.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level...
- CVSS:
- 4.4
- Affected:
- up to 4.19.1
- Fixed in:
- 4.19.2
- Disclosed:
- May 23, 2023
CVE-2023-2767 on NVD →
WordPress File Upload [wp-file-upload] < 4.16.4 (closed)
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress WordPress File Upload plugin (versions <= 4.16.3).
Update the WordPress WordPress File Upload plugin to the latest available version (at least 4.16.4).
- Affected:
- up to 4.16.4
- Fixed in:
- 4.16.4
- Disclosed:
- May 16, 2022
WordPress File Upload <= 4.16.3 - Cross-Site Scripting
medium
The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.16.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 5.4
- Affected:
- up to 4.16.3
- Fixed in:
- 4.16.4
- Disclosed:
- May 15, 2022
WordPress File Upload [wp-file-upload] < 4.16.4 (closed)
unknown
The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.16.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 4.16.4
- Fixed in:
- 4.16.4
- Disclosed:
- May 15, 2022
WordPress File Upload [wp-file-upload] < 4.16.3 (closed)
unknown
[en] The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to perform path traversal via a shortcode argument, which can then be used to upload a PHP code disguised as an image inside the auto-loaded directory of the plugin, resulting in arbitrary code exec...
- Affected:
- up to 4.16.3
- Fixed in:
- 4.16.3
- Disclosed:
- Mar 28, 2022
CVE-2021-24962 on NVD →
WordPress File Upload [wp-file-upload] < 4.16.3 (closed)
unknown
[en] The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 does not escape some of its shortcode argument, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks
- Affected:
- up to 4.16.3
- Fixed in:
- 4.16.3
- Disclosed:
- Mar 7, 2022
CVE-2021-24961 on NVD →
WordPress File Upload [wp-file-upload] < 4.16.3 (closed)
unknown
[en] The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allows users with a role as low as Contributor to configure the upload form in a way that allows uploading of SVG files, which could be then be used for Cross-Site Scripting attacks
- Affected:
- up to 4.16.3
- Fixed in:
- 4.16.3
- Disclosed:
- Mar 7, 2022
CVE-2021-24960 on NVD →
WordPress File Upload / WordPress File Upload Pro <= 4.16.2 - Authenticated (Contributor+) Path Traversal
medium
The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to perform path traversal via a shortcode argument, which can then be used to upload a PHP code disguised as an image inside the auto-loaded directory of the plugin, resulting in arbitrary code execution...
- CVSS:
- 6.5
- Affected:
- up to 4.16.2
- Fixed in:
- 4.16.3
- Disclosed:
- Mar 1, 2022
CVE-2021-24962 on NVD →
WordPress File Upload <= 4.16.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Malicious SVG
medium
The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allows users with a role as low as Contributor to configure the upload form in a way that allows uploading of SVG files, which could be then be used for Cross-Site Scripting attacks
- CVSS:
- 5.4
- Affected:
- up to 4.16.3
- Fixed in:
- 4.16.3
- Disclosed:
- Feb 14, 2022
CVE-2021-24960 on NVD →
WordPress File Upload <= 4.16.2 - Authenticated Stored Cross-Site Scripting via Shortcode
medium
The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 does not escape some of its shortcode argument, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks
- CVSS:
- 5.4
- Affected:
- up to 4.16.3
- Fixed in:
- 4.16.3
- Disclosed:
- Feb 14, 2022
CVE-2021-24961 on NVD →
WordPress File Upload <= 4.12.2 - Directory Traversal to Remote Code Execution
critical
An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call.
- CVSS:
- 9.8
- Affected:
- up to 4.12.2
- Fixed in:
- 4.13.0
- Disclosed:
- Mar 13, 2020
CVE-2020-10564 on NVD →
WordPress File Upload [wp-file-upload] < 4.13.0 (closed)
unknown
[en] An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call.
- Affected:
- up to 4.13.0
- Fixed in:
- 4.13.0
- Disclosed:
- Mar 13, 2020
CVE-2020-10564 on NVD →
WordPress File Upload [wp-file-upload] < 3.0.0 (closed)
unknown
[en] The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess files.
- Affected:
- up to 3.0.0
- Fixed in:
- 3.0.0
- Disclosed:
- Aug 22, 2019
CVE-2015-9340 on NVD →
WordPress File Upload [wp-file-upload] < 2.7.1 (closed)
unknown
[en] The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.
- Affected:
- up to 2.7.1
- Fixed in:
- 2.7.1
- Disclosed:
- Aug 22, 2019
CVE-2015-9339 on NVD →
WordPress File Upload [wp-file-upload] < 2.5.0 (closed)
unknown
[en] The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.
- Affected:
- up to 2.5.0
- Fixed in:
- 2.5.0
- Disclosed:
- Aug 22, 2019
CVE-2015-9338 on NVD →
WordPress File Upload [wp-file-upload] < 3.4.1 (closed)
unknown
[en] The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.
- Affected:
- up to 3.4.1
- Fixed in:
- 3.4.1
- Disclosed:
- Aug 22, 2019
CVE-2015-9341 on NVD →
WordPress File Upload [wp-file-upload] < 4.3.4 (closed)
unknown
[en] The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS.
- Affected:
- up to 4.3.4
- Fixed in:
- 4.3.4
- Disclosed:
- Apr 7, 2018
CVE-2018-9844 on NVD →
WordPress File Upload <= 4.3.3 - Stored Cross-Site Scripting
medium
The WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS.
- CVSS:
- 6.1
- Affected:
- up to 4.3.4
- Fixed in:
- 4.3.4
- Disclosed:
- Apr 6, 2018
CVE-2018-9844 on NVD →
WordPress File Upload [wp-file-upload] < 4.3.3 (closed)
unknown
[en] The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.
- Affected:
- up to 4.3.3
- Fixed in:
- 4.3.3
- Disclosed:
- Apr 1, 2018
CVE-2018-9172 on NVD →
WordPress File Upload <= 4.3.2 - Cross-Site Scripting via Shortcodes
medium
The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.
- CVSS:
- 4.1
- Affected:
- up to 4.3.3
- Fixed in:
- 4.3.3
- Disclosed:
- Mar 31, 2018
CVE-2018-9172 on NVD →
WordPress File Upload < 3.9.0 - Arbitrary File Upload
critical
The WordPress File Upload plugin is vulnerable to arbitrary file uploads due to insufficient file type validation in versions up to, and including, 3.8.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
- CVSS:
- 9.8
- Affected:
- up to 3.9.0
- Fixed in:
- 3.9.0
- Disclosed:
- Jun 23, 2016
WordPress File Upload [wp-file-upload] < 3.9.0 (closed)
unknown
The WordPress File Upload plugin is vulnerable to arbitrary file uploads due to insufficient file type validation in versions up to, and including, 3.8.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
- Affected:
- up to 3.9.0
- Fixed in:
- 3.9.0
- Disclosed:
- Jun 23, 2016
WordPress File Upload <= 3.4.0 - Arbitrary File Upload
critical
The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.
- CVSS:
- 9.8
- Affected:
- up to 3.4.1
- Fixed in:
- 3.4.1
- Disclosed:
- Oct 29, 2015
CVE-2015-9341 on NVD →
WordPress File Upload [wp-file-upload] < 3.4.1 (closed)
unknown
Because of this unauthenticated malicious file upload vulnerability, attackers can upload malicious payloads.
Upgrade the plugin.
- Affected:
- up to 3.4.1
- Fixed in:
- 3.4.1
- Disclosed:
- Oct 29, 2015
WordPress File Upload < 3.0.0 - Arbitrary File Upload
critical
The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess files.
- CVSS:
- 9.8
- Affected:
- up to 3.0.0
- Fixed in:
- 3.0.0
- Disclosed:
- Jul 2, 2015
CVE-2015-9340 on NVD →
WordPress File Upload < 2.7.1 - Arbitrary File Upload
high
The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.
- CVSS:
- 8.2
- Affected:
- up to 2.7.1
- Fixed in:
- 2.7.1
- Disclosed:
- May 9, 2015
CVE-2015-9339 on NVD →
WordPress File Upload <= 2.4.6 - Arbitrary File Upload
critical
The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.
- CVSS:
- 9.8
- Affected:
- up to 2.4.6
- Fixed in:
- 2.5.0
- Disclosed:
- Jan 23, 2015
CVE-2015-9338 on NVD →
WordPress File Upload <= 2.4.3 - Reflected Cross-Site Scripting
medium
The WordPress File Upload plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can su...
- CVSS:
- 6.1
- Affected:
- up to 2.4.3
- Fixed in:
- 2.4.4
- Disclosed:
- Aug 20, 2014
CVE-2014-125110 on NVD →
WordPress File Upload [wp-file-upload] < 2.4.2 (closed)
unknown
[en] Cross-site request forgery (CSRF) vulnerability in the WordPress File Upload plugin (wp-file-upload) before 2.4.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors. NOTE: some of these details are obtained from thi...
- Affected:
- up to 2.4.2
- Fixed in:
- 2.4.2
- Disclosed:
- Aug 12, 2014
CVE-2014-5199 on NVD →
WordPress File Upload < 2.4.2 - Cross-Site Request Forgery
medium
Cross-site request forgery (CSRF) vulnerability in the WordPress File Upload plugin (wp-file-upload) before 2.4.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors.
- CVSS:
- 6.3
- Affected:
- up to 2.4.2
- Fixed in:
- 2.4.2
- Disclosed:
- Aug 8, 2014
CVE-2014-5199 on NVD →
WordPress File Upload [wp-file-upload] < 4.24.1 (closed)
unknown
The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.24.0. This is due to missing or incorrect nonce validation on the wfu_ajax_action_save_shortcode function. This makes it possible for unauthenticated attackers to save shortcodes via a forg...
- Affected:
- up to 4.24.1
- Fixed in:
- 4.24.1
WordPress File Upload [wp-file-upload] < 4.24.14 (closed)
unknown
- Affected:
- up to 4.24.14
- Fixed in:
- 4.24.14
CVE-2024-9939 on NVD →
WordPress File Upload [wp-file-upload] < 3.9.0 (closed)
unknown
The WordPress File Upload WordPress plugin was affected by an Insufficient File Extension Blacklisting security vulnerability.
- Affected:
- up to 3.9.0
- Fixed in:
- 3.9.0