Iptanus / Wordpress File Upload
25 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-13494 | WordPress File Upload <= 4.25.2 - Cross-Site Request Forgery in wfu_file_details | MEDIUM | 4.3 | Feb 25, 2025 |
| CVE-2024-9939 | WordPress File Upload <= 4.24.13 - Unauthenticated Path Traversal to Arbitrary File Read in wfu_file_downloader.php | HIGH | 7.5 | Jan 8, 2025 |
| CVE-2024-11635 | WordPress File Upload <= 4.24.12 - Unuathenticated Remote Code Execution | CRITICAL | 9.8 | Jan 8, 2025 |
| CVE-2024-11613 | WordPress File Upload <= 4.24.15 - Unauthenticated Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion | CRITICAL | 9.8 | Jan 8, 2025 |
| CVE-2024-12719 | WordPress File Upload <= 4.24.15 - Missing Authorization to Authenticated (Subscriber+) Limited Path Traversal | MEDIUM | 4.3 | Jan 7, 2025 |
| CVE-2024-39639 | WordPress File Upload plugin <= 4.24.7 - Broken Access Control + CSRF vulnerability | MEDIUM | 4.3 | Nov 1, 2024 |
| CVE-2024-9047 | WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php | CRITICAL | 9.8 | Oct 12, 2024 |
| CVE-2024-7301 | WordPress File Upload <= 4.24.8 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload | HIGH | 7.2 | Aug 16, 2024 |
| CVE-2024-6494 | WordPress File Upload < 4.24.8 - Unauthenticated Stored XSS | MEDIUM | 6.1 | Aug 7, 2024 |
| CVE-2024-6651 | WordPress File Upload < 4.24.8 - Reflected XSS | MEDIUM | 6.1 | Aug 6, 2024 |
| CVE-2024-5852 | WordPress File Upload <= 4.24.7 - Authenticated (Contributor+) Directory Traversal | MEDIUM | 4.3 | Jul 16, 2024 |
| CVE-2024-2847 | WordPress File Upload <= 4.24.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | MEDIUM | 6.4 | Apr 9, 2024 |
| CVE-2023-4811 | WordPress File Upload < 4.23.3 - Author+ Stored Cross-Site Scripting | MEDIUM | 5.4 | Oct 16, 2023 |
| CVE-2023-2688 | WordPress File Upload / WordPress File Upload Pro <= 4.19.1 - Authenticated (Administrator+) Path Traversal | MEDIUM | 4.9 | Jun 9, 2023 |
| CVE-2023-2767 | WordPress File Upload / WordPress File Upload Pro <= 4.19.1 - Authenticated (Administrator+) Stored Cross-Site Scripting | MEDIUM | 5.5 | Jun 9, 2023 |
| CVE-2021-24962 | WordPress File Upload < 4.16.3 - Contributor+ Path Traversal to RCE | HIGH | 8.8 | Mar 28, 2022 |
| CVE-2021-24961 | WordPress File Upload < 4.16.3 - Contributor+ Stored Cross-Site Scripting via Shortcode | MEDIUM | 5.4 | Mar 7, 2022 |
| CVE-2021-24960 | WordPress File Upload < 4.16.3 - Contributor+ Stored Cross-Site Scripting via Malicious SVG | MEDIUM | 5.4 | Mar 7, 2022 |
| CVE-2020-10564 | An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted t… | CRITICAL | 9.8 | Mar 13, 2020 |
| CVE-2015-9338 | The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files. | HIGH | 7.5 | Aug 22, 2019 |
| CVE-2015-9339 | The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files. | HIGH | 7.5 | Aug 22, 2019 |
| CVE-2015-9340 | The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess… | HIGH | 7.5 | Aug 22, 2019 |
| CVE-2015-9341 | The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files. | HIGH | 7.5 | Aug 22, 2019 |
| CVE-2018-9844 | The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS. | MEDIUM | 6.1 | Apr 7, 2018 |
| CVE-2018-9172 | The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes. | MEDIUM | 5.4 | Apr 1, 2018 |
Showing 1 to 25 of 25 CVEs