CVE-2023-2688: Iptanus WordPress File Upload
Medium severity, CVSS 4.9. EPSS: 1.7% chance of exploitation in the next 30 days.
The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Path Traversal in versions up to, and including, 4.19.1 via the vulnerable parameter wfu_newpath. This allows administrator-level attackers to move files uploaded with the plugin (located in wp-content/uploads by default) outside of the web root.
Affected products
- Iptanus WordPress File Upload: up to and including 4.19.1
- Iptanus WordPress File Upload Pro: up to and including 4.19.1
Published 2023-06-09. Last modified 2026-06-17.