Cross-Site Scripting
12 records40%First: 2014. Latest: 2024.
Plugin security history
The Wordfence Intelligence dataset currently contains 30 vulnerability records associated with Iptanus File Upload, published between 2014 and 2025.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
Use this history
A history record does not establish whether the version installed on your website is affected. Enter the exact version in the checker, or add this software to a private Critical/High alert watchlist.
| Year | Records | Relative volume |
|---|---|---|
| 2014 | 2 | |
| 2015 | 4 | |
| 2016 | 1 | |
| 2018 | 2 | |
| 2020 | 1 | |
| 2022 | 4 | |
| 2023 | 4 | |
| 2024 | 7 | |
| 2025 | 5 |
| Severity | Records | Share |
|---|---|---|
| Critical | 8 | 26.7% |
| High | 4 | 13.3% |
| Medium | 18 | 60% |
First: 2014. Latest: 2024.
First: 2015. Latest: 2025.
First: 2020. Latest: 2025.
First: 2014. Latest: 2025.
First: 2024. Latest: 2025.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
4.25.34.24.144.25.04.24.124.24.94.24.84.24.64.24.14.23.34.19.24.16.44.16.34.13.04.3.44.3.33.9.03.4.13.0.02.7.12.5.02.4.42.4.2Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
[*, 3.0.0) | WordPress File Upload < 3.0.0 - Arbitrary File Upload | July 2, 2015 | 3.0.0 | Critical |
[*, 2.7.1) | WordPress File Upload < 2.7.1 - Arbitrary File Upload | May 9, 2015 | 2.7.1 | High |
*-2.4.6 | WordPress File Upload <= 2.4.6 - Arbitrary File Upload | January 23, 2015 | 2.5.0 | Critical |
*-2.4.3 | WordPress File Upload <= 2.4.3 - Reflected Cross-Site Scripting | August 20, 2014 | 2.4.4 | Medium |
[*, 2.4.2) | WordPress File Upload < 2.4.2 - Cross-Site Request Forgery | August 8, 2014 | 2.4.2 | Medium |
Selected source records
Published: February 24, 2025
Published: January 7, 2025
Published: January 7, 2025
Published: January 7, 2025
Published: January 6, 2025
Published: October 11, 2024
Published: August 15, 2024
Published: August 1, 2024
Published: January 7, 2025
Published: October 11, 2024
Published: January 23, 2015
Published: June 23, 2016
Published: January 7, 2025
Published: March 13, 2020
Published: October 29, 2015
Published: July 2, 2015
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.