VendorsIptanuswordpress_file_uploadany version
Vulnerabilities

Iptanus WordPress File Upload any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

25CVEs
CVE-2024-9047
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
Published 2024-10-12 · Analyzed
9.8EPSS 0.933
CVE-2020-10564
An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call.
Published 2020-03-13 · Modified
9.8EPSS 0.086
CVE-2024-11613
WordPress File Upload <= 4.24.15 - Unauthenticated Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion
Published 2025-01-08 · Modified
9.8EPSS 0.045
CVE-2024-11635
WordPress File Upload <= 4.24.12 - Unuathenticated Remote Code Execution
Published 2025-01-08 · Modified
9.8EPSS 0.015
CVE-2021-24962
WordPress File Upload < 4.16.3 - Contributor+ Path Traversal to RCE
Published 2022-03-28 · Modified
8.8EPSS 0.028
CVE-2015-9339
The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.
Published 2019-08-22 · Modified
7.5EPSS 0.014
CVE-2015-9340
The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess files.
Published 2019-08-22 · Modified
7.5EPSS 0.014
CVE-2015-9341
The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.
Published 2019-08-22 · Modified
7.5EPSS 0.014
CVE-2015-9338
The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.
Published 2019-08-22 · Modified
7.5EPSS 0.014
CVE-2024-9939
WordPress File Upload <= 4.24.13 - Unauthenticated Path Traversal to Arbitrary File Read in wfu_file_downloader.php
Published 2025-01-08 · Modified
7.5EPSS 0.011
CVE-2024-7301
WordPress File Upload <= 4.24.8 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload
Published 2024-08-16 · Analyzed
7.2EPSS 0.005
CVE-2024-2847
WordPress File Upload <= 4.24.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Published 2024-04-09 · Modified
6.4EPSS 0.004
CVE-2024-6651
WordPress File Upload < 4.24.8 - Reflected XSS
Published 2024-08-06 · Analyzed
6.1EPSS 0.150
CVE-2018-9844
The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS.
Published 2018-04-07 · Modified
6.11 PoCEPSS 0.036
CVE-2024-6494
WordPress File Upload < 4.24.8 - Unauthenticated Stored XSS
Published 2024-08-07 · Analyzed
6.1EPSS 0.004
CVE-2023-2767
WordPress File Upload / WordPress File Upload Pro <= 4.19.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
Published 2023-06-09 · Modified
5.5EPSS 0.004
CVE-2018-9172
The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.
Published 2018-04-01 · Modified
5.41 PoCEPSS 0.031
CVE-2021-24961
WordPress File Upload < 4.16.3 - Contributor+ Stored Cross-Site Scripting via Shortcode
Published 2022-03-07 · Modified
5.4EPSS 0.007
CVE-2021-24960
WordPress File Upload < 4.16.3 - Contributor+ Stored Cross-Site Scripting via Malicious SVG
Published 2022-03-07 · Modified
5.4EPSS 0.007
CVE-2023-4811
WordPress File Upload < 4.23.3 - Author+ Stored Cross-Site Scripting
Published 2023-10-16 · Modified
5.4EPSS 0.004
CVE-2023-2688
WordPress File Upload / WordPress File Upload Pro <= 4.19.1 - Authenticated (Administrator+) Path Traversal
Published 2023-06-09 · Modified
4.9EPSS 0.017
CVE-2024-5852
WordPress File Upload <= 4.24.7 - Authenticated (Contributor+) Directory Traversal
Published 2024-07-16 · Modified
4.3EPSS 0.007
CVE-2024-12719
WordPress File Upload <= 4.24.15 - Missing Authorization to Authenticated (Subscriber+) Limited Path Traversal
Published 2025-01-07 · Analyzed
4.3EPSS 0.004
CVE-2024-39639
WordPress File Upload plugin <= 4.24.7 - Broken Access Control + CSRF vulnerability
Published 2024-11-01 · Analyzed
4.3EPSS 0.003
CVE-2024-13494
WordPress File Upload <= 4.25.2 - Cross-Site Request Forgery in wfu_file_details
Published 2025-02-25 · Analyzed
4.3EPSS 0.002