Vulnerabilities (CVE)

Filtered by vendor Iptanus Subscribe
Filtered by product Wordpress File Upload
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-10564 1 Iptanus 1 Wordpress File Upload 2020-03-19 7.5 HIGH 9.8 CRITICAL
An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call.
CVE-2015-9339 1 Iptanus 1 Wordpress File Upload 2019-08-29 5.0 MEDIUM 7.5 HIGH
The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.
CVE-2015-9340 1 Iptanus 1 Wordpress File Upload 2019-08-29 5.0 MEDIUM 7.5 HIGH
The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess files.
CVE-2015-9338 1 Iptanus 1 Wordpress File Upload 2019-08-29 5.0 MEDIUM 7.5 HIGH
The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.
CVE-2015-9341 1 Iptanus 1 Wordpress File Upload 2019-08-29 5.0 MEDIUM 7.5 HIGH
The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.
CVE-2018-9844 1 Iptanus 1 Wordpress File Upload 2018-05-11 4.3 MEDIUM 6.1 MEDIUM
The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS.
CVE-2018-9172 1 Iptanus 1 Wordpress File Upload 2018-05-10 3.5 LOW 5.4 MEDIUM
The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.