Simple Dropbox Upload
Simple Dropbox Upload has one disclosed vulnerability in the WordSec catalog, all reported in 2013; it is fixed as of September 2026. Their average CVSS score is 9.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.
The most common weakness is Unrestricted Upload Of File With Dangerous Type, behind 1 of the records (100%).
The one issue recorded for Simple Dropbox Upload has a vendor fix available, so running the current release closes it.
All of these findings were reported by Amirh03in. Simple Dropbox Upload is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 3.5.2.
CVE-2013-5963Simple Dropbox Upload < 1.8.8.1 - Arbitrary File Upload
Read the full analysisVulnerability Records

Simple Dropbox Upload
Author
hiphopsmurf
This plugin lets you insert an upload form on your pages or in a post so visitors can upload files to your Dropbox account. Requirements WordPress 3.3.0 or higher PHP 5.0 or higher The wp-content/uploads directory needs to be writable by the plugin. This is likely already the case as WordPress stores your media and various other uploads here. Usage Go to Site Admin > Simple Dropbox (Optional)Enter the folder path you would like to save the files to on Dropbox. (Optional) Change the temporary path for files uploaded to your server before being uploaded to Dropbox. (Required) Enter the file extensions without periods for the files you want to allow users to upload separated by one space. (Optional) Enter a message you want displayed after the user uploads a file. (Optional) Choose a color for the message you want displayed after the user uploads a file. Choose whether or not to display upload form again after the first file has been uploaded to Dropbox. Choose whether or not to delete the file located on your server after it has been uploaded to Dropbox. Click Save options. If you have already authorized this plugin to use your Dropbox account you can skip to step 17 Click the Authorize button at the bottom of the screen. Click Continue to be taken to Dropbox. Once at Dropbox Click the Allow button so this plugin can link with your Dropbox account. Go to Site Admin > Simple Dropbox Click the Confirm button located at the bottom of the page to confirm your Dropbox account. You should see the email address used with your Dropbox account. If you don’t, Reset your settings and start over. Click Finish. Create a Page, Post or Widget to insert the shortcode into. Insert [simple-wp-dropbox] where you would like the form to display. Click Save or Publish. Visit the location to confirm everything is working properly. To-do list Multiple file upload Add ability to append uploaders username to file name/folder path Add ability to control file upload size Add ability to limit the number of submissions per user/day Restyle admin interface (Done|) Change database structure (Done|)
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C