CVE-2015-10138

CRITICAL

The Work The Flow File Upload plugin - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-10138. PoCs published by Claudio Viviani, including Metasploit module exploits/unix/webapp/wp_worktheflow_upload.

AI-analyzed exploit summary This Metasploit module exploits an arbitrary file upload vulnerability in the WordPress Work The Flow plugin (version 2.5.2), allowing remote code execution by uploading a malicious PHP file. The exploit leverages a multipart form data upload to bypass restrictions and deploy a payload.

Description

The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server and test files in versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

Exploits (1)

metasploit WORKING POC EXCELLENT
by Claudio Viviani · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/wp_worktheflow_upload.rb

This Metasploit module exploits an arbitrary file upload vulnerability in the WordPress Work The Flow plugin (version 2.5.2), allowing remote code execution by uploading a malicious PHP file. The exploit leverages a multipart form data upload to bypass restrictions and deploy a payload.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WordPress Work The Flow plugin 2.5.2
No auth needed
Prerequisites: Target running WordPress with vulnerable Work The Flow plugin (2.5.2) · Network access to the WordPress site
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.7925
EPSS Percentile 99.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-434
Status published
Products (2)
lynton_reed/Work The Flow File Upload < 2.5.2
lynton_reed/work_the_flow_file_upload < 2.5.2
Published Jul 19, 2025
Tracked Since Feb 18, 2026