Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
iptanus wordpress file upload vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-2688
The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Path Traversal in versions up to, and including, 4.19.1 via the vulnerable parameter wfu_newpath. This allows administrator-level malicious users to move files uploaded with the plugin...
Iptanus Wordpress File Upload Pro
Iptanus Wordpress File Upload
6.5
CVSSv2
CVE-2021-24962
The WordPress File Upload Free and Pro WordPress plugins prior to 4.16.3 allow users with a role as low as Contributor to perform path traversal via a shortcode argument, which can then be used to upload a PHP code disguised as an image inside the auto-loaded directory of the plu...
Iptanus Wordpress File Upload
Iptanus Wordpress File Upload Pro
NA
CVE-2023-2767
The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.19.1 due to insufficient input sanitization and output escaping. This makes it possible for authentic...
Iptanus Wordpress File Upload Pro
Iptanus Wordpress File Upload
3.5
CVSSv2
CVE-2021-24960
The WordPress File Upload WordPress plugin prior to 4.16.3, wordpress-file-upload-pro WordPress plugin prior to 4.16.3 allows users with a role as low as Contributor to configure the upload form in a way that allows uploading of SVG files, which could be then be used for Cross-Si...
Iptanus Wordpress File Upload
Iptanus Wordpress File Upload Pro
3.5
CVSSv2
CVE-2021-24961
The WordPress File Upload WordPress plugin prior to 4.16.3, wordpress-file-upload-pro WordPress plugin prior to 4.16.3 does not escape some of its shortcode argument, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks
Iptanus Wordpress File Upload
Iptanus Wordpress File Upload Pro
4.3
CVSSv2
CVE-2018-9844
The Iptanus WordPress File Upload plugin prior to 4.3.4 for WordPress mishandles Settings attributes, leading to XSS.
Iptanus Wordpress File Upload
1 EDB exploit
5
CVSSv2
CVE-2015-9339
The wp-file-upload plugin prior to 2.7.1 for WordPress has insufficient restrictions on upload of .js files.
Iptanus Wordpress File Upload
5
CVSSv2
CVE-2015-9341
The wp-file-upload plugin prior to 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.
Iptanus Wordpress File Upload
NA
CVE-2023-4811
The WordPress File Upload WordPress plugin prior to 4.23.3 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks.
Iptanus Wordpress File Upload
3.5
CVSSv2
CVE-2018-9172
The Iptanus WordPress File Upload plugin prior to 4.3.3 for WordPress mishandles shortcode attributes.
Iptanus Wordpress File Upload
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33228
CVE-2024-20361
log injection
bypass
CVE-2024-4985
CVE-2024-35223
CVE-2024-29849
CVE-2024-31893
IMAP
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »