Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

Iptanus File Upload Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 30 vulnerability records associated with Iptanus File Upload, published between 2014 and 2025.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

At a glance

Security Snapshot

30Total records
8Critical
4High
18Medium
0Low
0Informational
30Patched records
0Currently marked unpatched
2014-08-08First disclosure
2025-02-24Latest disclosure
27 of 30CVE coverage

Use this history

Check and watch Iptanus File Upload.

A history record does not establish whether the version installed on your website is affected. Enter the exact version in the checker, or add this software to a private Critical/High alert watchlist.

Year-by-Year Timeline

YearRecordsRelative volume
201422 records
201544 records
201611 records
201822 records
202011 records
202244 records
202344 records
202477 records
202555 records

Severity Breakdown

SeverityRecordsShare
Critical826.7%
High413.3%
Medium1860%

Vulnerability-Type Breakdown

Cross-Site Scripting

12 records40%

First: 2014. Latest: 2024.

Arbitrary File Upload

7 records23.3%

First: 2015. Latest: 2025.

Path Traversal

6 records20%

First: 2020. Latest: 2025.

CSRF

3 records10%

First: 2014. Latest: 2025.

Missing Authorization

2 records6.7%

First: 2024. Latest: 2025.

Patch Status

Patched
30
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 4.25.3
  • 4.24.14
  • 4.25.0
  • 4.24.12
  • 4.24.9
  • 4.24.8
  • 4.24.6
  • 4.24.1
  • 4.23.3
  • 4.19.2
  • 4.16.4
  • 4.16.3
  • 4.13.0
  • 4.3.4
  • 4.3.3
  • 3.9.0
  • 3.4.1
  • 3.0.0
  • 2.7.1
  • 2.5.0
  • 2.4.4
  • 2.4.2

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
[*, 3.0.0)WordPress File Upload < 3.0.0 - Arbitrary File UploadJuly 2, 20153.0.0Critical
[*, 2.7.1)WordPress File Upload < 2.7.1 - Arbitrary File UploadMay 9, 20152.7.1High
*-2.4.6WordPress File Upload <= 2.4.6 - Arbitrary File UploadJanuary 23, 20152.5.0Critical
*-2.4.3WordPress File Upload <= 2.4.3 - Reflected Cross-Site ScriptingAugust 20, 20142.4.4Medium
[*, 2.4.2)WordPress File Upload < 2.4.2 - Cross-Site Request ForgeryAugust 8, 20142.4.2Medium

Selected source records

Latest Records

MediumCVE-2024-13494

WordPress File Upload <= 4.25.2 - Cross-Site Request Forgery in wfu_file_details

Published: February 24, 2025

Affected versions
*-4.25.2
Patched versions
4.25.3
Original Wordfence record
CriticalCVE-2024-11635

WordPress File Upload <= 4.24.12 - Unuathenticated Remote Code Execution

Published: January 7, 2025

Affected versions
*-4.24.12
Patched versions
4.24.14
Original Wordfence record
CriticalCVE-2024-11613

WordPress File Upload <= 4.24.15 - Unauthenticated Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion

Published: January 7, 2025

Affected versions
*-4.24.15
Patched versions
4.25.0
Original Wordfence record
HighCVE-2024-9939

WordPress File Upload <= 4.24.13 - Unauthenticated Path Traversal to Arbitrary File Read in wfu_file_downloader.php

Published: January 7, 2025

Affected versions
*-4.24.13
Patched versions
4.24.14
Original Wordfence record
MediumCVE-2024-12719

WordPress File Upload <= 4.24.15 - Missing Authorization to Authenticated (Subscriber+) Limited Path Traversal

Published: January 6, 2025

Affected versions
*-4.24.15
Patched versions
4.25.0
Original Wordfence record
CriticalCVE-2024-9047

WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php

Published: October 11, 2024

Affected versions
*-4.24.11
Patched versions
4.24.12
Original Wordfence record
HighCVE-2024-7301

WordPress File Upload <= 4.24.8 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload

Published: August 15, 2024

Affected versions
*-4.24.8
Patched versions
4.24.9
Original Wordfence record
MediumCVE-2024-39639

WordPress File Upload <= 4.24.7 - Missing Authorization

Published: August 1, 2024

Affected versions
*-4.24.7
Patched versions
4.24.8
Original Wordfence record

Highest-Severity Records

CriticalCVE-2024-11613

WordPress File Upload <= 4.24.15 - Unauthenticated Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion

Published: January 7, 2025

Affected versions
*-4.24.15
Patched versions
4.25.0
Original Wordfence record
CriticalCVE-2024-9047

WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php

Published: October 11, 2024

Affected versions
*-4.24.11
Patched versions
4.24.12
Original Wordfence record
CriticalCVE-2015-9338

WordPress File Upload <= 2.4.6 - Arbitrary File Upload

Published: January 23, 2015

Affected versions
*-2.4.6
Patched versions
2.5.0
Original Wordfence record
Critical

WordPress File Upload < 3.9.0 - Arbitrary File Upload

Published: June 23, 2016

Affected versions
[*, 3.9.0)
Patched versions
3.9.0
Original Wordfence record
CriticalCVE-2024-11635

WordPress File Upload <= 4.24.12 - Unuathenticated Remote Code Execution

Published: January 7, 2025

Affected versions
*-4.24.12
Patched versions
4.24.14
Original Wordfence record
CriticalCVE-2020-10564

WordPress File Upload <= 4.12.2 - Directory Traversal to Remote Code Execution

Published: March 13, 2020

Affected versions
*-4.12.2
Patched versions
4.13.0
Original Wordfence record
CriticalCVE-2015-9341

WordPress File Upload <= 3.4.0 - Arbitrary File Upload

Published: October 29, 2015

Affected versions
[*, 3.4.1)
Patched versions
3.4.1
Original Wordfence record
CriticalCVE-2015-9340

WordPress File Upload < 3.0.0 - Arbitrary File Upload

Published: July 2, 2015

Affected versions
[*, 3.0.0)
Patched versions
3.0.0
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory