📦 Wordpress File Upload

by Iptanus

🔍 What is Wordpress File Upload?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-11635

CRITICAL CVSS 9.8 Jan 8, 2025

This vulnerability allows unauthenticated attackers to execute arbitrary code on WordPress servers running the vulnerable File Upload plugin. All WordPress sites using this plugin up to version 4.24.1...

CVE-2024-11613

CRITICAL CVSS 9.8 Jan 8, 2025

This vulnerability in the WordPress File Upload plugin allows unauthenticated attackers to execute arbitrary code, read sensitive files, and delete files on affected WordPress sites. All WordPress sit...

CVE-2024-9047

CRITICAL CVSS 9.8 Oct 12, 2024

The WordPress File Upload plugin has a path traversal vulnerability in wfu_file_downloader.php that allows unauthenticated attackers to read or delete files outside intended directories. This affects ...

CVE-2024-7301

HIGH CVSS 7.2 Aug 16, 2024

The WordPress File Upload plugin versions up to 4.24.8 contain a stored cross-site scripting vulnerability in SVG file uploads. Unauthenticated attackers can upload malicious SVG files containing Java...

CVE-2021-24962

HIGH CVSS 8.8 Mar 28, 2022

This vulnerability in WordPress File Upload plugins allows users with Contributor role or higher to perform path traversal attacks via shortcode arguments. Attackers can upload PHP code disguised as i...

CVE-2024-13494

MEDIUM CVSS 4.3 Feb 25, 2025

This CSRF vulnerability in WordPress File Upload plugin allows attackers to modify user data details for uploaded files by tricking administrators into clicking malicious links. All WordPress sites us...

CVE-2024-39639

MEDIUM CVSS 4.3 Nov 1, 2024

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the WordPress File Upload plugin that allows attackers to trick authenticated users into performing unauthorized file uploads or...

CVE-2024-6651

MEDIUM CVSS 6.1 Aug 6, 2024

This vulnerability in the WordPress File Upload plugin allows attackers to inject malicious scripts via a reflected cross-site scripting (XSS) attack. When high-privilege users like administrators cli...

CVE-2024-5852

MEDIUM CVSS 4.3 Jul 16, 2024

The WordPress File Upload plugin contains a directory traversal vulnerability that allows authenticated attackers with Contributor-level access or higher to upload limited files to arbitrary locations...