Skip to content
Noroxi

Iptanus File Upload

wp-file-upload · plugin

Known security vulnerabilities for Iptanus File Upload. Find out in seconds which version runs on your site with WP Lens.

20 known vulnerabilities

4 critical · 12 exploitable without logging in · 3 with public exploit code · latest Oct 1, 2026

Listed on wordpress.org · latest 5.2.0 · last updated Sep 26, 2026 · 10K+ installs

wordpress.org status checked on Oct 2, 2026

Vulnerabilities

  • CVE-2024-9047unauthenticated≤ 4.24.11

    WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php

    Critical 9.8
  • CVE-2020-10564unauthenticated

    An issue was discovered in the File Upload plugin before 4.13.0 for WordPress.

    Critical 9.8
  • CVE-2026-62071unauthenticated≤ 5.1.10

    WordPress WordPress File Upload plugin <= 5.1.10 - SQL Injection vulnerability

    Critical 9.3
  • CVE-2026-66447unauthenticated≤ 5.1.7

    WordPress WordPress File Upload plugin <= 5.1.7 - SQL Injection vulnerability

    Critical 9.3
  • CVE-2024-9939unauthenticated≤ 4.24.13

    WordPress File Upload <= 4.24.13 - Unauthenticated Path Traversal to Arbitrary File Read in wfu_file_downloader.php

    High 7.5
  • CVE-2015-9340unauthenticated

    The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm,

    High 7.5
  • CVE-2015-9339unauthenticated

    The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.

    High 7.5
  • CVE-2015-9338unauthenticated

    The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.

    High 7.5
  • CVE-2015-9341unauthenticated

    The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.

    High 7.5
  • CVE-2014-5199

    Cross-site request forgery (CSRF) vulnerability in the WordPress File Upload plugin (wp-file-upload) before 2.4.2 for WordPress allows remot

    Medium 6.8
  • CVE-2024-7301unauthenticated≤ 4.24.8

    WordPress File Upload <= 4.24.8 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload

    Medium 6.1
  • CVE-2018-9844unauthenticated · needs a click

    The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS.

    Medium 6.1
  • CVE-2023-2767admin≤ 4.19.1

    WordPress File Upload / WordPress File Upload Pro <= 4.19.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

    Medium 5.5
  • CVE-2018-9172login required

    The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.

    Medium 5.4
  • CVE-2024-2847contributor+≤ 4.24.5

    WordPress File Upload <= 4.24.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    Medium 5.4
  • CVE-2023-2688admin≤ 4.19.1

    WordPress File Upload / WordPress File Upload Pro <= 4.19.1 - Authenticated (Administrator+) Path Traversal

    Medium 4.9
  • CVE-2024-13494unauthenticated · needs a click≤ 4.25.2

    WordPress File Upload <= 4.25.2 - Cross-Site Request Forgery in wfu_file_details

    Medium 4.3
  • CVE-2024-12719subscriber+≤ 4.24.15

    WordPress File Upload <= 4.24.15 - Missing Authorization to Authenticated (Subscriber+) Limited Path Traversal

    Medium 4.3
  • CVE-2024-5852contributor+≤ 4.24.7

    WordPress File Upload <= 4.24.7 - Authenticated (Contributor+) Directory Traversal

    Medium 4.3
  • CVE-2024-39639login required≤ 4.24.7

    WordPress File Upload plugin <= 4.24.7 - Broken Access Control + CSRF vulnerability

    Low 3.5

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory