Vulnerabilities > Iptanus > Wordpress File Upload > 4.16.3

DATE CVE VULNERABILITY TITLE RISK
2023-10-16 CVE-2023-4811 Unspecified vulnerability in Iptanus Wordpress File Upload
The WordPress File Upload WordPress plugin before 4.23.3 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks.
network
low complexity
iptanus
5.4
2023-06-09 CVE-2023-2688 Unspecified vulnerability in Iptanus Wordpress File Upload and Wordpress File Upload PRO
The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Path Traversal in versions up to, and including, 4.19.1 via the vulnerable parameter wfu_newpath.
network
low complexity
iptanus
4.9
2023-06-09 CVE-2023-2767 Cross-site Scripting vulnerability in Iptanus Wordpress File Upload and Wordpress File Upload PRO
The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.19.1 due to insufficient input sanitization and output escaping.
network
low complexity
iptanus CWE-79
5.5