CVE-2024-6494: Iptanus WordPress File Upload

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

The WordPress File Upload WordPress plugin before 4.24.8 does not properly sanitize and escape certain parameters, which could allow unauthenticated users to execute stored cross-site scripting (XSS) attacks.

Affected products

  • Iptanus WordPress File Upload: before 4.24.8 (fixed in 4.24.8)

Published 2024-08-07. Last modified 2026-06-17.