Iptanus File Upload

Iptanus File Upload has 32 disclosed vulnerabilities in the WordSec catalog, reported between 2014 and 2026; all 32 are fixed as of September 2026. Their average CVSS score is 6.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 8 critical and 6 high. 2024 was the busiest year with 7 disclosures.

The most common weakness is Cross-Site Scripting, behind 12 of the records (38%). Other recurring categories include Path Traversal, Unrestricted Upload Of File With Dangerous Type.

Every one of the 32 issues recorded for Iptanus File Upload has a vendor fix available, so running the current release closes all known holes.

17 independent researchers contributed these findings, most of them (3) reported by abrahack. Iptanus File Upload is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

01234567891009.12.2013Today08.08.20146.3WordPress File Upload < 2.4.2 - Cross-Site Request Forgery CVSS 6.3 · 08.08.201420.08.20146.1WordPress File Upload <= 2.4.3 - Reflected Cross-Site Scripting CVSS 6.1 · 20.08.201423.01.20159.8WordPress File Upload <= 2.4.6 - Arbitrary File Upload CVSS 9.8 · 23.01.201509.05.20158.2WordPress File Upload < 2.7.1 - Arbitrary File Upload CVSS 8.2 · 09.05.201502.07.20159.8WordPress File Upload < 3.0.0 - Arbitrary File Upload CVSS 9.8 · 02.07.201529.10.20159.8WordPress File Upload <= 3.4.0 - Arbitrary File Upload CVSS 9.8 · 29.10.201523.06.20169.8WordPress File Upload < 3.9.0 - Arbitrary File Upload CVSS 9.8 · 23.06.201631.03.20184.1WordPress File Upload <= 4.3.2 - Cross-Site Scripting via Shortcodes CVSS 4.1 · 31.03.201806.04.20186.1WordPress File Upload <= 4.3.3 - Stored Cross-Site Scripting CVSS 6.1 · 06.04.201813.03.20209.8WordPress File Upload <= 4.12.2 - Directory Traversal to Remote Code Execution CVSS 9.8 · 13.03.202014.02.20225.4WordPress File Upload <= 4.16.2 - Authenticated Stored Cross-Site Scripting via Shortcode CVSS 5.4 · 14.02.20225.4WordPress File Upload <= 4.16.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Malicious SVG CVSS 5.4 · 14.02.202201.03.20226.5WordPress File Upload / WordPress File Upload Pro <= 4.16.2 - Authenticated (Contributor+) Path Traversal CVSS 6.5 · 01.03.202215.05.20225.4WordPress File Upload <= 4.16.3 - Cross-Site Scripting CVSS 5.4 · 15.05.202223.05.20234.9WordPress File Upload / WordPress File Upload Pro <= 4.19.1 - Authenticated (Administrator+) Path Traversal CVSS 4.9 · 23.05.20234.4WordPress File Upload / WordPress File Upload Pro <= 4.19.1 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 23.05.202312.09.20234.4Wordpress File Upload <= 4.23.2 - Authenticated(Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 12.09.202314.11.20234.3Wordpress File Upload 4.24.0 - Cross-Site Request Forgery CVSS 4.3 · 14.11.202329.03.20246.4WordPress File Upload <= 4.24.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CVSS 6.4 · 29.03.202415.07.20244.3WordPress File Upload <= 4.24.7 - Authenticated (Contributor+) Directory Traversal CVSS 4.3 · 15.07.202416.07.20246.1WordPress File Upload <= 4.24.7 - Reflected Cross-Site Scripting CVSS 6.1 · 16.07.20247.2WordPress File Upload <= 4.24.7 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 16.07.202401.08.20245.4WordPress File Upload <= 4.24.7 - Missing Authorization CVSS 5.4 · 01.08.202415.08.20247.2WordPress File Upload <= 4.24.8 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload CVSS 7.2 · 15.08.202411.10.20249.8WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php CVSS 9.8 · 11.10.202406.01.20254.3WordPress File Upload <= 4.24.15 - Missing Authorization to Authenticated (Subscriber+) Limited Path Traversal CVSS 4.3 · 06.01.202507.01.20259.8WordPress File Upload <= 4.24.15 - Unauthenticated Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion CVSS 9.8 · 07.01.20257.5WordPress File Upload <= 4.24.13 - Unauthenticated Path Traversal to Arbitrary File Read in wfu_file_downloader.php CVSS 7.5 · 07.01.20259.8WordPress File Upload <= 4.24.12 - Unuathenticated Remote Code Execution CVSS 9.8 · 07.01.202524.02.20254.3WordPress File Upload <= 4.25.2 - Cross-Site Request Forgery in wfu_file_details CVSS 4.3 · 24.02.202503.08.20267.5File Upload <= 5.1.7 - Unauthenticated SQL Injection CVSS 7.5 · 03.08.202605.08.20267.5Iptanus File Upload <= 5.1.7 - Unauthenticated SQL Injection CVSS 7.5 · 05.08.2026

Strategic Overview

Avg CVSSMedium
6.8/ 10
Patch Coverage100%
Open

0

Fixed

32

Get automatic notifications for all Iptanus File Upload vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2024-11635

WordPress File Upload <= 4.24.12 - Unuathenticated Remote Code Execution

Read the full analysis

Vulnerability Records

32 records
2026-08-05 00:00CVE-2026-66447
7.5
High
darooYes
2026-08-03 00:00CVE-2026-17044
7.5
High
Pedro PinhoYes
2025-02-24 00:00CVE-2024-13494
4.3
Medium
Tim CoenYes
2025-01-07 18:43CVE-2024-11635
9.8
Critical
abrahackYes
2025-01-07 00:00CVE-2024-11613
9.8
Critical
abrahackYes
2025-01-07 00:00CVE-2024-9939
7.5
High
abrahackYes
2025-01-06 00:00CVE-2024-12719
4.3
Medium
Lucio SáYes
2024-10-11 00:00CVE-2024-9047
9.8
Critical
Arkadiusz HydzikYes
2024-08-15 16:20CVE-2024-7301
7.2
High
wesley (wcraft)Yes
2024-08-01 00:00CVE-2024-39639
5.4
Medium
emadYes
Showing 1–10 of 32 reports
Iptanus File Upload banner
Latestv5.1.10

Iptanus File Upload

nickboss

Author

nickboss

4.4(117)
88/100
Last Updated
2026-08-03 (1mo ago)
Active Installs
10,000+
Downloads
1,460,434
Requires WP
3.0+
Requires PHP
0+
Tested up to
WP 7.0.4
Created
2013-12-09 (13y ago)

With this plugin you or other users can upload files to your site from any page, post or sidebar easily and securely. Simply put the shortcode [wordpress_file_upload] to the contents of any WordPress page / post or add the plugin’s widget in any sidebar and you will be able to upload files to any directory inside wp-contents of your WordPress site. You can add custom fields to submit additional data together with the uploaded file. You can use it to capture screenshots or video from your webcam and upload it to the website (for browsers that support this feature). You can even use it as a simple contact (or any other type of) form to submit data without including a file. The plugin displays the list of uploaded files in a separate top-level menu in Dashboard and includes a file browser to access and manage the uploaded files (only for admins currently). Several filters and actions before and after file upload enable extension of its capabilities. The characteristics of the plugin are: It uses the latest HTML5 technology, however it will also work with old browsers and mobile phones. It provides a nice upload form using Material UI React components. It is compliant with the General Data Protection Regulation (GDPR) of the European Union. It can be added in posts, pages or sidebars (as a widget). It can capture and upload screenshots or video from the device’s camera. It supports additional form fields (like checkboxes, text fields, email fields, dropdown lists etc). It can be used as a simple contact form to submit data (a selection of file can be optional). It produces notification messages and e-mails. It supports selection of destination folder from a list of subfolders. Upload progress can be monitored with a progress bar. Upload process can be cancelled at any time. It supports redirection to another url after successful upload. There can be more than one instances of the shortcode in the same page or post. Uploaded files can be added to Media or be attached to the current page. Uploaded files can be saved to an FTP location (ftp and sftp protocols supported). It is highly customizable with many (more than 50) options. It supports filters and actions before and after file upload. It contains a visual editor for customizing the plugin easily without any knowledge of shortcodes or programming It supports logging of upload events or management of files, which can be viewed by admins through the Dashboard. It includes an Uploaded Files top-level menu item in the Dashboard, from where admins can view the uploaded files. It includes a file browser in the Dashboard, from where admins can manage the files. It supports multilingual characters and localization. The plugin is translated in the following languages: Portuguese, kindly provided by Rui Alao German French, kindly provided by Thomas Bastide of http://www.omicronn.fr/ and improved by other contributors Serbian, kindly provided by Andrijana Nikolic of http://webhostinggeeks.com/ Dutch, kindly provided by Ruben Heynderycx Chinese, kindly provided by Yingjun Li Spanish, kindly provided by Marton Italian, kindly provided by Enrico Marcolini https://www.marcuz.it/ Polish Swedish, kindly provided by Leif Persson Persian, kindly provided by Shahriyar Modami http://chabokgroup.com Greek Please note that the plugin contains minified CSS and Javascript files in order to reduce its size and speed-up performance. The unminified version of these files can be found here. The source code of the compiled React files of the plugin can be found here. Please also note that old desktop browsers or mobile browsers may not support all of the above functionalities. In order to get full functionality use the latest versions browsers, supporting HTML5, AJAX and CSS3. For additional features, such as multiple file upload, very large file upload, drag and drop of files, captcha, detailed upload progress bars, list of uploaded files, image gallery and custom css please consider Iptanus File Upload Professional. Please visit the Other Notes section for customization options of this plugin. Plugin Customization Options Please visit the support page of the plugin for detailed description of customization options. Requirements The plugin requires to have Javascript enabled in your browser. For Internet Explorer you also need to have Active-X enabled. Please note that old desktop browsers or mobile browsers may not support all of the plugin’s features. In order to get full functionality use the latest versions of browsers, supporting HTML5, AJAX and CSS3. External services The plugin connects to Iptanus servers to retrieve information about the latest version of the plugin. It does not send any user data. It just receives the latest version of the plugin. The service is provided by the owner of the plugin, Iptanus. Terms of Service. Privacy Policy.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C