Known Vulnerabilities for Wordpress File Upload by Wordpress File Upload Project
Listed below are 1 of the newest known vulnerabilities associated with "Wordpress File Upload" by "Wordpress File Upload Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-58480 json | Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that... | Not Provided | 2026-07-08 | 2026-07-08 |
| CVE-2026-15282 json | The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in t... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-15158 json | The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.4... | Not Provided | 2026-07-09 | 2026-07-09 |
| CVE-2026-14894 json | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up t... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-14489 json | The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the conn... | Not Provided | 2026-07-08 | 2026-07-08 |
| CVE-2026-13430 json | The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and incl... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-13369 json | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the attach_files() function in v... | Not Provided | 2026-07-02 | 2026-07-02 |
| CVE-2026-13352 json | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress p... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-13001 json | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio... | Not Provided | 2026-07-14 | 2026-07-14 |
| CVE-2026-12968 json | The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticate... | Not Provided | 2026-07-22 | 2026-07-22 |