Medium severity4.3NVD Advisory· Published Jul 16, 2024· Updated Apr 8, 2026
CVE-2024-5852
CVE-2024-5852
Description
The WordPress File Upload plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.24.7 via the 'uploadpath' parameter of the wordpress_file_upload shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload limited files to arbitrary locations on the web server.
Affected products
1- cpe:2.3:a:iptanus:wordpress_file_upload:*:*:*:*:*:wordpress:*:*Range: <4.24.8
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- plugins.trac.wordpress.org/changesetnvdPatch
- www.wordfence.com/threat-intel/vulnerabilities/id/39bb69e0-fb18-4737-9eb7-bda2b5bc16a2nvdThird Party Advisory
News mentions
0No linked articles in our index yet.