CVE-2020-10564: Iptanus WordPress File Upload
Critical severity, CVSS 9.8. EPSS: 8.6% chance of exploitation in the next 30 days.
An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call.
Affected products
- Iptanus WordPress File Upload: before 4.13.0 (fixed in 4.13.0)
Published 2020-03-13. Last modified 2026-06-17.