Protect uploads

The WordPress uploads directory is not protected, allowing anyone to view its contents. The Hide My WP plugin adds an index.php file or htaccess to the root of the directory to prevent unauthorized access. The plugin supports multiple languages and the htaccess option may be disabled depending on server settings.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Access violation vulnerability in Protect uploads 0.3

    Fixed

    The Protect uploads plugin for WordPress had a security flaw that allowed attackers to make changes to the plugin settings. Even though the file did not allow access to sensitive information or enabl...

    Read More