Critical 9.8 Closed
2025-07-19< 2.5.3
CVE-2015-10138
Minimum safe version
2.5.3
Update to 2.5.3 or later to address 8 fixable vulnerabilities
CVE-2015-10138
Work The Flow File Upload < 2.4 - wp-admin/admin-ajax.php accept_file_types Parameter Manipulation File Upload Restriction Bypass
Work-The-Flow 1.2.1 - Shell Upload
Work The Flow File Upload <= 2.5.2 - Shell Upload
Work The Flow <= 2.3.1 - Arbitrary File Upload
Work The Flow File Upload <= 2.5.2 - Arbitrary File Upload
WordPress Work The Flow Plugin - Upload Vulnerability
WordPress Work The Flow File Upload 2.5.2 - Arbitrary File Upload
WordPress Work The Flow Plugin 1.2.1 - Arbitrary File Upload