Cross-Site Scripting
12 records40%First: 2014. Latest: 2024.
Plugin security history
The Wordfence Intelligence dataset currently contains 30 vulnerability records associated with Iptanus File Upload, published between 2014 and 2025.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
Use this history
A history record does not establish whether the version installed on your website is affected. Enter the exact version in the checker, or add this software to a private Critical/High alert watchlist.
| Year | Records | Relative volume |
|---|---|---|
| 2014 | 2 | |
| 2015 | 4 | |
| 2016 | 1 | |
| 2018 | 2 | |
| 2020 | 1 | |
| 2022 | 4 | |
| 2023 | 4 | |
| 2024 | 7 | |
| 2025 | 5 |
| Severity | Records | Share |
|---|---|---|
| Critical | 8 | 26.7% |
| High | 4 | 13.3% |
| Medium | 18 | 60% |
First: 2014. Latest: 2024.
First: 2015. Latest: 2025.
First: 2020. Latest: 2025.
First: 2014. Latest: 2025.
First: 2024. Latest: 2025.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
4.25.34.24.144.25.04.24.124.24.94.24.84.24.64.24.14.23.34.19.24.16.44.16.34.13.04.3.44.3.33.9.03.4.13.0.02.7.12.5.02.4.42.4.2Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-4.25.2 | WordPress File Upload <= 4.25.2 - Cross-Site Request Forgery in wfu_file_details | February 24, 2025 | 4.25.3 | Medium |
*-4.24.12 | WordPress File Upload <= 4.24.12 - Unuathenticated Remote Code Execution | January 7, 2025 | 4.24.14 | Critical |
*-4.24.13 | WordPress File Upload <= 4.24.13 - Unauthenticated Path Traversal to Arbitrary File Read in wfu_file_downloader.php | January 7, 2025 | 4.24.14 | High |
*-4.24.15 | WordPress File Upload <= 4.24.15 - Unauthenticated Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion | January 7, 2025 | 4.25.0 | Critical |
*-4.24.15 | WordPress File Upload <= 4.24.15 - Missing Authorization to Authenticated (Subscriber+) Limited Path Traversal | January 6, 2025 | 4.25.0 | Medium |
*-4.24.11 | WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php | October 11, 2024 | 4.24.12 | Critical |
*-4.24.8 | WordPress File Upload <= 4.24.8 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload | August 15, 2024 | 4.24.9 | High |
*-4.24.7 | WordPress File Upload <= 4.24.7 - Missing Authorization | August 1, 2024 | 4.24.8 | Medium |
*-4.24.7 | WordPress File Upload <= 4.24.7 - Reflected Cross-Site Scripting | July 16, 2024 | 4.24.8 | Medium |
*-4.24.7 | WordPress File Upload <= 4.24.7 - Unauthenticated Stored Cross-Site Scripting | July 16, 2024 | 4.24.8 | High |
*-4.24.7 | WordPress File Upload <= 4.24.7 - Authenticated (Contributor+) Directory Traversal | July 15, 2024 | 4.24.8 | Medium |
*-4.24.5 | WordPress File Upload <= 4.24.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | March 29, 2024 | 4.24.6 | Medium |
*-4.24.0 | Wordpress File Upload 4.24.0 - Cross-Site Request Forgery | November 14, 2023 | 4.24.1 | Medium |
[*, 4.23.3) | Wordpress File Upload <= 4.23.2 - Authenticated(Administrator+) Stored Cross-Site Scripting | September 12, 2023 | 4.23.3 | Medium |
*-4.19.1 | WordPress File Upload / WordPress File Upload Pro <= 4.19.1 - Authenticated (Administrator+) Path Traversal | May 23, 2023 | 4.19.2 | Medium |
*-4.19.1 | WordPress File Upload / WordPress File Upload Pro <= 4.19.1 - Authenticated (Administrator+) Stored Cross-Site Scripting | May 23, 2023 | 4.19.2 | Medium |
*-4.16.3 | WordPress File Upload <= 4.16.3 - Cross-Site Scripting | May 15, 2022 | 4.16.4 | Medium |
*-4.16.2 | WordPress File Upload / WordPress File Upload Pro <= 4.16.2 - Authenticated (Contributor+) Path Traversal | March 1, 2022 | 4.16.3 | Medium |
[*, 4.16.3) | WordPress File Upload <= 4.16.2 - Authenticated Stored Cross-Site Scripting via Shortcode | February 14, 2022 | 4.16.3 | Medium |
[*, 4.16.3) | WordPress File Upload <= 4.16.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Malicious SVG | February 14, 2022 | 4.16.3 | Medium |
*-4.12.2 | WordPress File Upload <= 4.12.2 - Directory Traversal to Remote Code Execution | March 13, 2020 | 4.13.0 | Critical |
[*, 4.3.4) | WordPress File Upload <= 4.3.3 - Stored Cross-Site Scripting | April 6, 2018 | 4.3.4 | Medium |
[*, 4.3.3) | WordPress File Upload <= 4.3.2 - Cross-Site Scripting via Shortcodes | March 31, 2018 | 4.3.3 | Medium |
[*, 3.9.0) | WordPress File Upload < 3.9.0 - Arbitrary File Upload | June 23, 2016 | 3.9.0 | Critical |
[*, 3.4.1) | WordPress File Upload <= 3.4.0 - Arbitrary File Upload | October 29, 2015 | 3.4.1 | Critical |
Selected source records
Published: February 24, 2025
Published: January 7, 2025
Published: January 7, 2025
Published: January 7, 2025
Published: January 6, 2025
Published: October 11, 2024
Published: August 15, 2024
Published: August 1, 2024
Published: January 7, 2025
Published: October 11, 2024
Published: January 23, 2015
Published: June 23, 2016
Published: January 7, 2025
Published: March 13, 2020
Published: October 29, 2015
Published: July 2, 2015
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.