---
id: CVE-2015-10138
title: >-
  The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary
  file uploads due to missing file type validation in the
  jQuery-File-Upload-9.5.0 server and test files in versions up to, and
  including, 2.5.2
summary: >-
  The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary
  file uploads due to missing file type validation in the
  jQuery-File-Upload-9.5.0 server and test files in versions up to, and
  including, 2.5.2. This makes it p…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-434
vendor: lyntonreed
product: work_the_flow_file_upload
affected:
  - work_the_flow_file_upload <= 2.5.2
published: '2025-07-19'
updated: '2026-07-27'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2015-10138'
references:
  - url: 'https://packetstormsecurity.com/files/131294/'
    label: security@wordfence.com
  - url: 'https://packetstormsecurity.com/files/131512/'
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=1127456%40work-the-flow-file-upload&new=1127456%40work-the-flow-file-upload&sfp_email=&sfph_mail=
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=1127457%40work-the-flow-file-upload&new=1127457%40work-the-flow-file-upload&sfp_email=&sfph_mail=
    label: security@wordfence.com
  - url: 'https://wpscan.com/vulnerability/a49a81a9-3d4b-4c8d-b719-fc513aceecc6'
    label: security@wordfence.com
  - url: >-
      https://www.acunetix.com/vulnerabilities/web/wordpress-plugin-work-the-flow-file-upload-arbitrary-file-upload-2-5-2/
    label: security@wordfence.com
  - url: >-
      https://www.homelab.it/index.php/2015/04/04/wordpress-work-the-flow-file-upload-vulnerability/
    label: security@wordfence.com
  - url: >-
      https://www.rapid7.com/db/modules/exploit/unix/webapp/wp_worktheflow_upload/
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/eb271cc8-01ec-45eb-9d6f-efc55c7c3923?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - exploit-available
epss: 0.03618
epssPercentile: 0.89008
ingestedAt: '2026-07-27T16:21:36.795Z'
exploits:
  metasploit:
    - exploit/unix/webapp/wp_worktheflow_upload
  checkedAt: '2026-09-21T15:26:54.561Z'
exploitAvailable: true
---

## Overview

The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server and test files in versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

## Affected

- `work_the_flow_file_upload <= 2.5.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
