CVE-2014-5199: WordPress File Upload Project WordPress File Upload
Medium severity, CVSS 6.8. EPSS: 1% chance of exploitation in the next 30 days.
Cross-site request forgery (CSRF) vulnerability in the WordPress File Upload plugin (wp-file-upload) before 2.4.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors. NOTE: some of these details are obtained from third party information.
Affected products
- WordPress File Upload Project WordPress File Upload: up to and including 2.4.1
Published 2014-08-12. Last modified 2026-06-17.