WordPress security by component
WordPress File Upload
Plugin description
WordPress File Upload adds file upload forms and file management features for collecting files through WordPress pages and posts.
WordPress File Upload (wordpress-file-upload) is a WordPress plugin with 15 published CVE records in this archive. The latest tracked vulnerability was published Feb 25, 2025; the highest published CVSS base score is 9.8.
Plugin slug:
wordpress-file-uploadLatest vulnerability
CVE-2024-13494: WordPress File Upload: Cross-site request forgery
WordPress File Upload is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
| Safe version |
|
||
|---|---|---|---|
| Feb 25, 2025 |
CVE-2024-13494
WordPress File Upload: Cross-site request forgery
WordPress File Upload is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jan 08, 2025 |
CVE-2024-9939
WordPress File Upload: Filesystem traversal
WordPress File Upload is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Jan 08, 2025 |
CVE-2024-11635
WordPress File Upload: Code execution
WordPress File Upload is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Jan 08, 2025 |
CVE-2024-11613
WordPress File Upload: Filesystem traversal
WordPress File Upload is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Oct 12, 2024 |
CVE-2024-9047
WordPress File Upload: Filesystem traversal
WordPress File Upload is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Aug 07, 2024 |
CVE-2024-6494
WordPress File Upload: Cross-site scripting
WordPress File Upload is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Aug 06, 2024 |
CVE-2024-6651
WordPress File Upload: Cross-site scripting
WordPress File Upload is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Jul 16, 2024 |
CVE-2024-5852
WordPress File Upload: Filesystem traversal
WordPress File Upload is affected by filesystem traversal. Exploitation requires an authenticated contributor account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Apr 09, 2024 |
CVE-2024-2847
WordPress File Upload: Cross-site scripting
WordPress File Upload is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Oct 16, 2023 |
CVE-2023-4811
WordPress File Upload: Cross-site scripting
WordPress File Upload is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Jun 09, 2023 |
CVE-2023-2767
Wordpress File Upload: Cross-site scripting
Wordpress File Upload is affected by cross-site scripting. Exploitation requires an authenticated administrator account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.4
NVD5.5
|
| Jun 09, 2023 |
CVE-2023-2688
Wordpress File Upload: Filesystem traversal
Wordpress File Upload is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE4.9
NVD4.9
|
| Mar 28, 2022 |
CVE-2021-24962
Wordpress File Upload: Filesystem traversal
Wordpress File Upload is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVEPending
NVD8.8
|
| Mar 07, 2022 |
CVE-2021-24961
WordPress File Upload: Cross-site scripting
WordPress File Upload is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD5.4
|
| Mar 07, 2022 |
CVE-2021-24960
WordPress File Upload: Cross-site scripting
WordPress File Upload is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD5.4
|