Access violation vulnerability in WordPress File Upload 4.19.1

The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are not secure in versions up to 4.19.1. If someone with administrator-level access uses the vulnerable parameter wfu_newpath, they can move files uploaded with the plugin (which are located in wp-content/uploads by default) to a different location outside of the web root. This means any confidential information uploaded with the plugin could be accessed by people who should not have access to it.

Detected in:

WordPress File Upload Pro fixed vulnerable versions: >= * <= 4.19.1
WordPress File Upload open vulnerable versions: >= * <= 4.19.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.