PLUGIN SECURITY
Is File Upload Types safe?
Easily allow WordPress to accept and upload any file type extension or MIME type, including custom file types.
What this plugin does
- Slug:
file-upload-types - Author: Syed Balkhi
- 40000+ active installs
- 80/100 rating (20 reviews on wordpress.org)
- 257192 all-time downloads
- On WordPress.org since 2020-02-12
attachmentsfile uploadfilesmimeupload
Maintenance status
- Latest known version: 1.5.0
- Last updated: 2026-05-25 1:46pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.0+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
1 known CVE on file for File Upload Types. Reported between 2024 and 2024.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-10016 | File Upload Types by WPForms [file-upload-types] < 1.5.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 1.5.0 | 1.5.0 | 2024-10-24 | ✓ fixed in latest |
How to fix it
Keep File Upload Types updated — 1.5.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Export media with selected content (by DKZR) — 40000+ active installs — 90/100 (93) — max PHP 8.4
- Lightbox with PhotoSwipe — 20000+ active installs — 98/100 (115) — max PHP 8.4
- Unique Headers — 10000+ active installs — 98/100 (160) — max PHP 8.4
- Media Deduper — 9000+ active installs — 76/100 (44)
- Download Attachments — 8000+ active installs — 90/100 (46) — max PHP <8.0
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.