
Relocate Upload Security & Risk Analysis
wordpress.org/plugins/relocate-uploadWordpress uploads media to one pre-set folder. Relocate Upload lets you switch media to other folders.
Is Relocate Upload Safe to Use in 2026?
Use With Caution
Score 55/100Relocate Upload has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "relocate-upload" plugin, version 0.24.1, presents a mixed security posture. While it demonstrates good practices by utilizing prepared statements for all SQL queries and including a nonce check on its single AJAX handler, significant concerns arise from its output escaping and vulnerability history. The static analysis reveals that 100% of output is not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly reflected in the output. Furthermore, the plugin has a history of two known CVEs, with one critical vulnerability remaining unpatched, specifically related to Cross-Site Request Forgery (CSRF) and PHP Remote File Inclusion. This historical pattern suggests a recurring weakness in secure coding practices, particularly concerning input validation and file handling, and the unpatched critical vulnerability is a severe immediate risk.
While the attack surface is limited and most entry points have some form of protection, the lack of proper output escaping and the unpatched critical vulnerability significantly elevate the risk associated with this plugin. The vulnerability history, including a critical PHP Remote File Inclusion flaw, is particularly worrying and indicates a potential for severe compromise if exploited. Therefore, users should exercise extreme caution with this plugin, prioritize updating to a version that addresses the known critical vulnerability, and ideally, consider alternatives until its security posture is demonstrably improved.
Key Concerns
- Unpatched Critical CVE
- 100% Unescaped Output
- Flow with unsanitized paths
- Historical PHP RFI vulnerability
- Historical CSRF vulnerability
Relocate Upload Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Relocate Upload <= 0.24.1 - Cross-Site Request Forgery
Relocate Upload < 0.20 - Remote File Inclusion
Relocate Upload Release Timeline
Relocate Upload Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Relocate Upload Attack Surface
AJAX Handlers 1
WordPress Hooks 6
Maintenance & Trust
Relocate Upload Maintenance & Trust
Maintenance Signals
Community Trust
Relocate Upload Alternatives
Add From Server
add-from-server
Add From Server is designed to help ease the pain of bad web hosts, allowing you to upload files via FTP or SSH and later import them into WordPress.
Disable Bloat for WordPress & WooCommerce
disable-dashboard-for-woocommerce
All-in-One solution to speed up your WordPress & WooCommerce. Remove unnecessary features and make your site faster and cleaner.
Disable WP Notification
disable-wp-notification
Best wordpress plugin to remove all the admin panel notifications in just one click. Including the theme and plugin update notification.
Prevent Direct Access – Protect WordPress Files
prevent-direct-access
A simple way to prevent search engines and the public from indexing and accessing your files without complex user authentication.
Hide Admin Toolbar
hide-admin-toolbar
This plugin is used to hide admin toolbar from website. It will hide that bar when you are logged in and viewing the site.
Relocate Upload Developer Profile
2 plugins · 110 total installs
How We Detect Relocate Upload
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/relocate-upload/js/relocate-upload.js/wp-content/plugins/relocate-upload/js/relocate-upload.jsrelocate-upload/js/relocate-upload.js?ver=HTML / DOM Fingerprints
media_idru_folderru_request_move