The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Path Traversal in versions up to, and including, 4.19.1 via the vulnerable parameter wfu_newpath. This allows administrator-level attackers to move files uploaded with the plugin (located in wp-content/uploads by default) outside of the web root.
CVE ID: CVE-2023-2688
CVSS Base Severity: MEDIUM
CVSS Base Score: 4.9
Vendor: nickboss
Product: WordPress File Upload
EPSS Score: 0.08% (probability of being exploited)
EPSS Percentile: 37.72% (scored less or equal to compared to others)
EPSS Date: 2025-02-04 (when was this score calculated)