Software intelligence
Important: Wp File Upload appearing in this catalog does not mean your website is affected. Exposure depends on your installed version. How SiteRespond intelligence works
Tracked advisories
32
Latest advisory
5 August 2026
CISA KEV matches
0
In this WordPress feed
WordPress slug
wp-file-upload
Plugin
This catalog lists 32 known advisories affecting Wp File Upload. The most recent was published on 5 August 2026. If you use this software, compare your installed version against the affected ranges on each advisory and update to a fixed release outside those ranges. SiteRespond Defence checks your actual installed version when the plugin is connected — listing here does not by itself mean your site is vulnerable.
Iptanus File Upload <= 5.1.7 - Unauthenticated SQL Injection
May allow attackers to read or modify database contents beyond intended access.
Published 5 August 2026
File Upload <= 5.1.7 - Unauthenticated SQL Injection
May allow attackers to read or modify database contents beyond intended access.
Published 3 August 2026
WordPress File Upload <= 4.25.2 - Cross-Site Request Forgery in wfu_file_details
May allow attackers to run arbitrary code on the server if exploited.
Published 24 February 2025
Known Wp File Upload advisories published by month.
CVE-2014-125110 · Published 20 August 2014
Affected versions: ≤ 2.4.3
CVE-2014-5199 · Published 8 August 2014
Affected versions: < 2.4.2
SiteRespond Defence matches your installed Wp File Upload version against this catalog when the Defence plugin is connected to your WordPress site.