Vulnerabilities > Iptanus > Wordpress File Upload PRO > 4.16.3
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-06-09 | CVE-2023-2688 | Unspecified vulnerability in Iptanus Wordpress File Upload and Wordpress File Upload PRO The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Path Traversal in versions up to, and including, 4.19.1 via the vulnerable parameter wfu_newpath. | 4.9 |
2023-06-09 | CVE-2023-2767 | Cross-site Scripting vulnerability in Iptanus Wordpress File Upload and Wordpress File Upload PRO The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.19.1 due to insufficient input sanitization and output escaping. | 5.5 |