N/A
2026-02-03< 2.1.40
WP FOFT Loader <= 2.1.39 - Authenticated (Author+) Arbitrary File Upload
Minimum safe version
2.1.40
Update to 2.1.40 or later to address 4 fixable vulnerabilities
WP FOFT Loader <= 2.1.39 - Authenticated (Author+) Arbitrary File Upload
WordPress WP FOFT Loader Plugin < 2.1.29 is vulnerable to Cross Site Scripting (XSS)
WordPress WP FOFT Loader plugin < 2.1.21 - Sensitive Information Disclosure vulnerability
WordPress WP FOFT Loader plugin < 2.1.21 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability