Iptanus File Upload
wp-file-upload · plugin
Known security vulnerabilities for Iptanus File Upload. Find out in seconds which version runs on your site with WP Lens.
20 known vulnerabilities
4 critical · 12 exploitable without logging in · 3 with public exploit code · latest Oct 1, 2026
Listed on wordpress.org · latest 5.2.0 · last updated Sep 26, 2026 · 10K+ installs
wordpress.org status checked on Oct 2, 2026
Vulnerabilities
- Critical 9.8
CVE-2024-9047unauthenticated≤ 4.24.11
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
- Critical 9.8
CVE-2020-10564unauthenticated
An issue was discovered in the File Upload plugin before 4.13.0 for WordPress.
- Critical 9.3
CVE-2026-62071unauthenticated≤ 5.1.10
WordPress WordPress File Upload plugin <= 5.1.10 - SQL Injection vulnerability
- Critical 9.3
CVE-2026-66447unauthenticated≤ 5.1.7
WordPress WordPress File Upload plugin <= 5.1.7 - SQL Injection vulnerability
- High 7.5
CVE-2024-9939unauthenticated≤ 4.24.13
WordPress File Upload <= 4.24.13 - Unauthenticated Path Traversal to Arbitrary File Read in wfu_file_downloader.php
- High 7.5
CVE-2015-9340unauthenticated
The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm,
- High 7.5
CVE-2015-9339unauthenticated
The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.
- High 7.5
CVE-2015-9338unauthenticated
The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.
- High 7.5
CVE-2015-9341unauthenticated
The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.
- Medium 6.8
Cross-site request forgery (CSRF) vulnerability in the WordPress File Upload plugin (wp-file-upload) before 2.4.2 for WordPress allows remot
- Medium 6.1
CVE-2024-7301unauthenticated≤ 4.24.8
WordPress File Upload <= 4.24.8 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload
- Medium 6.1
CVE-2018-9844unauthenticated · needs a click
The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS.
- Medium 5.5
CVE-2023-2767admin≤ 4.19.1
WordPress File Upload / WordPress File Upload Pro <= 4.19.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
- Medium 5.4
CVE-2018-9172login required
The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.
- Medium 5.4
CVE-2024-2847contributor+≤ 4.24.5
WordPress File Upload <= 4.24.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
- Medium 4.9
CVE-2023-2688admin≤ 4.19.1
WordPress File Upload / WordPress File Upload Pro <= 4.19.1 - Authenticated (Administrator+) Path Traversal
- Medium 4.3
CVE-2024-13494unauthenticated · needs a click≤ 4.25.2
WordPress File Upload <= 4.25.2 - Cross-Site Request Forgery in wfu_file_details
- Medium 4.3
CVE-2024-12719subscriber+≤ 4.24.15
WordPress File Upload <= 4.24.15 - Missing Authorization to Authenticated (Subscriber+) Limited Path Traversal
- Medium 4.3
CVE-2024-5852contributor+≤ 4.24.7
WordPress File Upload <= 4.24.7 - Authenticated (Contributor+) Directory Traversal
- Low 3.5
CVE-2024-39639login required≤ 4.24.7
WordPress File Upload plugin <= 4.24.7 - Broken Access Control + CSRF vulnerability
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).