Extension WordPress
Vulnérabilités Iptanus File Upload
Cette page rassemble les failles publiées pour Iptanus File Upload, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Iptanus File Upload
30 fiches
WordPress File Upload <= 4.25.2 – Cross-Site Request Forgery in wfu_file_details
The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.25.2. This is due to missing or incorrect nonce validation on the 'wfu_file_details' function. This makes it possible…
*-4.25.2
4.25.3
24/02/2025
WordPress File Upload <= 4.24.12 – Unuathenticated Remote Code Execution
The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie parameter. This makes it possible for unauthenticated attackers to execute code on the…
*-4.24.12
4.24.14
07/01/2025
WordPress File Upload <= 4.24.13 – Unauthenticated Path Traversal to Arbitrary File Read in wfu_file_downloader.php
The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.13 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read files outside of the originally intended directory.
*-4.24.13
4.24.14
07/01/2025
WordPress File Upload <= 4.24.15 – Unauthenticated Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion
The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion in all versions up to, and including, 4.24.15 via the 'wfu_file_downloader.php' file. This is due to lack of…
*-4.24.15
4.25.0
07/01/2025
WordPress File Upload <= 4.24.15 – Missing Authorization to Authenticated (Subscriber+) Limited Path Traversal
The WordPress File Upload plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wfu_ajax_action_read_subfolders' function in all versions up to, and including, 4.24.15. This makes it possible for authenticated…
*-4.24.15
4.25.0
06/01/2025
WordPress File Upload <= 4.24.11 – Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read or delete files outside of the originally…
*-4.24.11
4.24.12
11/10/2024
WordPress File Upload <= 4.24.8 – Unauthenticated Stored Cross-Site Scripting via SVG File Upload
The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.24.8 due to insufficient input sanitization and output escaping. This makes it possible for…
*-4.24.8
4.24.9
15/08/2024
WordPress File Upload <= 4.24.7 – Missing Authorization
The WordPress File Upload plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wfu_ajax_action_save_shortcode() function in versions up to, and including, 4.24.7. This makes it possible for authenticated attackers, with contributor-level…
*-4.24.7
4.24.8
01/08/2024
WordPress File Upload <= 4.24.7 – Unauthenticated Stored Cross-Site Scripting
The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom text fileds in all versions up to, and including, 4.24.7 due to insufficient input sanitization and output escaping. This makes it possible for…
*-4.24.7
4.24.8
16/07/2024
WordPress File Upload <= 4.24.7 – Reflected Cross-Site Scripting
The WordPress File Upload plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dir' parameter in all versions up to, and including, 4.24.7 due to insufficient input sanitization and output escaping. This makes it possible for…
*-4.24.7
4.24.8
16/07/2024
WordPress File Upload <= 4.24.7 – Authenticated (Contributor+) Directory Traversal
The WordPress File Upload plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.24.7 via the 'uploadpath' parameter of the wordpress_file_upload shortcode. This makes it possible for authenticated attackers, with Contributor-level access…
*-4.24.7
4.24.8
15/07/2024
WordPress File Upload <= 4.24.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.24.5 due to insufficient input sanitization and output escaping on user supplied attributes. This…
*-4.24.5
4.24.6
29/03/2024
Wordpress File Upload 4.24.0 – Cross-Site Request Forgery
The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.24.0. This is due to missing or incorrect nonce validation on the wfu_ajax_action_save_shortcode function. This makes it possible…
*-4.24.0
4.24.1
14/11/2023
Wordpress File Upload <= 4.23.2 – Authenticated(Administrator+) Stored Cross-Site Scripting
The Wordpress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute in versions up to, and including, 4.23.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
[*, 4.23.3)
4.23.3
12/09/2023
WordPress File Upload / WordPress File Upload Pro <= 4.19.1 – Authenticated (Administrator+) Path Traversal
The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Path Traversal in versions up to, and including, 4.19.1 via the vulnerable parameter wfu_newpath. This allows administrator-level attackers to move files uploaded with…
*-4.19.1
4.19.2
23/05/2023
WordPress File Upload / WordPress File Upload Pro <= 4.19.1 – Authenticated (Administrator+) Stored Cross-Site Scripting
The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.19.1 due to insufficient input sanitization and output escaping. This makes…
*-4.19.1
4.19.2
23/05/2023
WordPress File Upload <= 4.16.3 – Cross-Site Scripting
The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.16.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts…
*-4.16.3
4.16.4
15/05/2022
WordPress File Upload / WordPress File Upload Pro <= 4.16.2 – Authenticated (Contributor+) Path Traversal
The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to perform path traversal via a shortcode argument, which can then be used to upload a PHP code…
*-4.16.2
4.16.3
01/03/2022
WordPress File Upload <= 4.16.2 – Authenticated Stored Cross-Site Scripting via Shortcode
The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 does not escape some of its shortcode argument, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks
[*, 4.16.3)
4.16.3
14/02/2022
WordPress File Upload <= 4.16.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Malicious SVG
The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allows users with a role as low as Contributor to configure the upload form in a way that allows uploading of SVG files, which could…
[*, 4.16.3)
4.16.3
14/02/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.