Access violation vulnerability in Big File Uploads – Increase Maximum File Upload Size 2.1.2

A plugin for WordPress called “Big File Uploads – Increase Maximum File Upload Size” has a security issue in all versions up to 2.1.2. This is because the plugin doesn’t properly protect a file path in an error message. This means that someone with authorized access to the website could potentially find out the full path of the website, which could be used for further attacks. However, this information alone is not enough to cause harm to the website and another vulnerability would be needed for an attack to be successful.

Detected in:

Big File Uploads – Increase Maximum File Upload Size fixed vulnerable versions: >= * <= 2.1.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.