CVE-2020-10564: Iptanus WordPress File Upload

Critical severity, CVSS 9.8. EPSS: 8.6% chance of exploitation in the next 30 days.

An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call.

Affected products

  • Iptanus WordPress File Upload: before 4.13.0 (fixed in 4.13.0)

Published 2020-03-13. Last modified 2026-06-17.