Input validation vulnerability in WordPress File Upload 4.24.15

The WordPress File Upload plugin for WordPress has a security issue that allows hackers to run their own code on the server. This can happen because the plugin does not properly check the ‘source’ parameter and lets users choose any directory they want. This vulnerability affects all versions up to 4.24.15 and can also allow hackers to read or delete files.

Detected in:

WordPress File Upload open vulnerable versions: >= * <= 4.24.15

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.