Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Iptanus Subscribe
Filtered by product Wordpress File Upload
Total 10 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24962 1 Iptanus 2 Wordpress File Upload, Wordpress File Upload Pro 2022-04-04 6.5 MEDIUM 8.8 HIGH
The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to perform path traversal via a shortcode argument, which can then be used to upload a PHP code disguised as an image inside the auto-loaded directory of the plugin, resulting in arbitrary code execution.
CVE-2021-24961 1 Iptanus 2 Wordpress File Upload, Wordpress File Upload Pro 2022-03-11 3.5 LOW 5.4 MEDIUM
The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 does not escape some of its shortcode argument, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks
CVE-2021-24960 1 Iptanus 2 Wordpress File Upload, Wordpress File Upload Pro 2022-03-11 3.5 LOW 5.4 MEDIUM
The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allows users with a role as low as Contributor to configure the upload form in a way that allows uploading of SVG files, which could be then be used for Cross-Site Scripting attacks
CVE-2020-10564 1 Iptanus 1 Wordpress File Upload 2020-03-19 7.5 HIGH 9.8 CRITICAL
An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call.
CVE-2015-9338 1 Iptanus 1 Wordpress File Upload 2019-08-29 5.0 MEDIUM 7.5 HIGH
The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.
CVE-2015-9339 1 Iptanus 1 Wordpress File Upload 2019-08-29 5.0 MEDIUM 7.5 HIGH
The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.
CVE-2015-9340 1 Iptanus 1 Wordpress File Upload 2019-08-29 5.0 MEDIUM 7.5 HIGH
The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess files.
CVE-2015-9341 1 Iptanus 1 Wordpress File Upload 2019-08-29 5.0 MEDIUM 7.5 HIGH
The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.
CVE-2018-9844 1 Iptanus 1 Wordpress File Upload 2018-05-11 4.3 MEDIUM 6.1 MEDIUM
The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS.
CVE-2018-9172 1 Iptanus 1 Wordpress File Upload 2018-05-10 3.5 LOW 5.4 MEDIUM
The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.