WordPress File Upload

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in WordPress File Upload 4.25.2

    Fixed

    The File Upload plugin for WordPress has a security vulnerability that allows attackers to modify user data associated with uploaded files. This vulnerability exists in all versions up to and includi...

    Read More
  • Input validation vulnerability in WordPress File Upload 4.24.12

    Fixed

    The WordPress File Upload plugin for WordPress has a security issue that allows hackers to run their own code on the server without being logged in. This vulnerability exists in all versions up to an...

    Read More
  • Access violation vulnerability in WordPress File Upload 4.24.13

    Fixed

    The WordPress File Upload plugin for WordPress has a security issue called Path Traversal. This issue affects all versions up to and including 4.24.13 through the file wfu_file_downloader.php. This m...

    Read More
  • Input validation vulnerability in WordPress File Upload 4.24.15

    Fixed

    The WordPress File Upload plugin for WordPress has a security issue that allows hackers to run their own code on the server. This can happen because the plugin does not properly check the 'source' pa...

    Read More
  • Access violation vulnerability in WordPress File Upload 4.24.15

    Fixed

    The WordPress File Upload plugin has a security issue where people can access data without permission. This is because it doesn't check if someone has the right capability to use the 'wfu_ajax_action...

    Read More
  • Access violation vulnerability in WordPress File Upload 4.24.11

    Fixed

    The WordPress File Upload plugin has a security issue called Path Traversal, which affects all versions up to 4.24.11. This means that attackers who are not logged in can access and delete files from...

    Read More
  • Input validation vulnerability in WordPress File Upload 4.24.8

    Fixed

    The WordPress File Upload plugin for WordPress has a security issue that affects all versions up to 4.24.8. This vulnerability is known as Stored Cross-Site Scripting and it happens when unauthentica...

    Read More
  • Input validation vulnerability in WordPress File Upload 4.24.7

    Fixed

    The WordPress File Upload plugin for WordPress has a security issue that could allow attackers to inject harmful web scripts into pages. This can happen if a user clicks on a link and is not properly...

    Read More
  • Input validation vulnerability in WordPress File Upload 4.24.7

    Fixed

    The WordPress File Upload plugin is not secure and can be easily hacked by anyone. This is because it doesn't properly check for harmful code in custom text fields. Hackers can use this vulnerability...

    Read More
  • Access violation vulnerability in WordPress File Upload 4.24.7

    Fixed

    and inject malicious JavaScript code into posts or pages. The WordPress File Upload plugin for WordPress has a security issue that could allow unauthorized people to access it. This is because there ...

    Read More
  • Access violation vulnerability in WordPress File Upload 4.24.7

    Fixed

    The WordPress File Upload plugin is not secure and can be exploited by anyone with Contributor-level access or higher. This vulnerability allows them to upload files to any location on the web server...

    Read More
  • Input validation vulnerability in WordPress File Upload 2.4.3

    Fixed

    The WordPress File Upload plugin has a security vulnerability that allows attackers to inject malicious scripts into web pages. This can happen if a user is tricked into clicking on a link.

    Read More
  • Input validation vulnerability in WordPress File Upload 4.24.5

    Fixed

    The WordPress File Upload plugin is not secure and can be exploited by hackers. This is because the plugin does not properly clean up user input and output, allowing attackers with certain access lev...

    Read More
  • Input validation vulnerability in WordPress File Upload 4.24.0

    Fixed

    The WordPress File Upload (WFU) plugin is a program for WordPress websites that allows users to upload files directly from the website. Unfortunately, all versions of the plugin up to and including 4...

    Read More
  • Input validation vulnerability in WordPress File Upload 4.23.3

    Fixed

    The Wordpress File Upload plugin for WordPress has a security issue that can lead to malicious code being stored in certain websites. It affects versions up to, and including, 4.23.2. If an attacker ...

    Read More
  • Access violation vulnerability in WordPress File Upload 4.19.1

    Fixed

    The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are not secure in versions up to 4.19.1. If someone with administrator-level access uses the vulnerable parameter wfu_new...

    Read More
  • Input validation vulnerability in WordPress File Upload 4.19.1

    Fixed

    The WordPress File Upload and WordPress File Upload Pro plugins for WordPress have a security vulnerability in versions up to and including 4.19.1. Attackers with administrator-level permissions can ...

    Read More
  • Input validation vulnerability in WordPress File Upload 3.0.0

    Fixed

    The plugin ""wp-file-upload"" for WordPress computer software had too few rules about what kind of files could be uploaded

    Read More
  • Input validation vulnerability in WordPress File Upload 3.4.1

    Fixed

    The wp-file-upload plugin

    Read More
  • Input validation vulnerability in WordPress File Upload 4.3.4

    Fixed

    The WordPress File Upload plugin

    Read More
  • Access violation vulnerability in WordPress File Upload 4.12.2

    Fixed

    A security issue was found in a plugin called File Upload

    Read More
  • Access violation vulnerability in WordPress File Upload 4.16.2

    Fixed

    The WordPress File Upload plugins (Free and Pro) released before version 4.16.3 could allow people with a Contributor role or higher to upload malicious code on a website. This malicious code could be...

    Read More
  • Input validation vulnerability in WordPress File Upload 2.4.2

    Fixed

    The WordPress File Upload plugin (wp-file-upload) before 2.4.2 for WordPress had a vulnerability that allowed people from outside the website to take control of the settings. This could have allowed t...

    Read More
  • Input validation vulnerability in WordPress File Upload 3.9.0

    Fixed

    The WordPress File Upload plugin contains a vulnerability that allows people without permission to upload any type of file to a website using the plugin. This vulnerability exists in versions of the ...

    Read More
  • Input validation vulnerability in WordPress File Upload 2.4.6

    Fixed

    The wp-file-upload plugin for WordPress had a problem where it did not have enough restrictions on what types of files people could upload. Before version 2.5.0 of the plugin

    Read More
  • Input validation vulnerability in WordPress File Upload 4.3.3

    Fixed

    The Iptanus plugin for WordPress

    Read More
  • Input validation vulnerability in WordPress File Upload 4.16.3

    Fixed

    The WordPress File Upload plugin for WordPress is vulnerable to a security issue called Cross-Site Scripting. This issue exists in versions of the plugin up to and including version 4.16.3. It occurs...

    Read More
  • Input validation vulnerability in WordPress File Upload 2.7.1

    Fixed

    The wp-file-upload plugin

    Read More
  • Input validation vulnerability in WordPress File Upload 4.16.3

    Fixed

    Read More
  • Input validation vulnerability in WordPress File Upload 4.16.3

    Fixed

    The WordPress File Upload and WordPress File Upload Pro plugins

    Read More