Big File Uploads – Increase Maximum File Upload Size Security & Risk Analysis

wordpress.org/plugins/tuxedo-big-file-uploads

Enable large file uploads in the built-in WordPress media uploader via file chunking, and set maximum upload file size to any value based on user role …

100K active installs v2.1.7 PHP 5.6+ WP 5.6+ Updated Sep 2, 2025
increase-file-size-limitincrease-upload-limitmax-upload-file-sizepost-max-sizeupload-limit
99
A · Safe
CVEs total2
Unpatched0
Last CVESep 6, 2024
Download
Safety Verdict

Is Big File Uploads – Increase Maximum File Upload Size Safe to Use in 2026?

Generally Safe

Score 99/100

Big File Uploads – Increase Maximum File Upload Size has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Sep 6, 2024Updated 7mo ago
Risk Assessment

The "tuxedo-big-file-uploads" v2.1.7 plugin exhibits a generally good security posture, particularly in its handling of AJAX requests and SQL queries. The static analysis shows a robust implementation of authorization checks for all identified AJAX entry points, and all SQL queries are properly prepared, which significantly mitigates common injection vulnerabilities. Furthermore, the absence of critical or high-severity taint flows suggests that user-supplied data is being handled with reasonable care, and the code does not appear to expose sensitive information through obvious unsanitized paths.

However, the plugin's vulnerability history is a notable concern. Having two known medium-severity CVEs, even if currently patched, indicates a recurring pattern of security weaknesses. The historical vulnerability types, Exposure of Sensitive Information to an Unauthorized Actor and Cross-Site Request Forgery (CSRF), are significant and can lead to serious security breaches. While the current version may have patched these, the history suggests a potential for such issues to re-emerge or for new vulnerabilities to be introduced in future updates if not addressed with stringent security practices.

In conclusion, the "tuxedo-big-file-uploads" v2.1.7 plugin demonstrates strengths in its defensive coding practices for new vulnerabilities, particularly in its secure handling of AJAX and SQL. Nevertheless, the historical presence of medium-severity vulnerabilities warrants caution. The plugin's development team should prioritize a thorough security review and robust testing process to prevent the recurrence of past vulnerability types.

Key Concerns

  • Known medium vulnerabilities historically
  • Potential for past vulnerability types to recur
  • 19% of output not properly escaped
Vulnerabilities
2

Big File Uploads – Increase Maximum File Upload Size Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-8538medium · 4.3Exposure of Sensitive Information to an Unauthorized Actor

Big File Uploads <= 2.1.2 - Authenticated (Author+) Full Path Disclosure

Sep 6, 2024 Patched in 2.1.3 (1d)
CVE-2023-47792medium · 4.3Cross-Site Request Forgery (CSRF)

Big File Uploads <= 2.1.1 - Cross-Site Request Forgery via actions

Nov 14, 2023 Patched in 2.1.2 (70d)
Code Analysis
Analyzed Mar 16, 2026

Big File Uploads – Increase Maximum File Upload Size Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
23
98 escaped
Nonce Checks
5
Capability Checks
15
File Operations
13
External Requests
0
Bundled Libraries
0

Output Escaping

81% escaped121 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
ajax_chunk_receiver (tuxedo_big_file_uploads.php:487)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Big File Uploads – Increase Maximum File Upload Size Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 6

authwp_ajax_bffu_handle_promo_actionclasses\class-promo-notice.php:9
authwp_ajax_bfu_chunkertuxedo_big_file_uploads.php:115
authwp_ajax_bfu_file_scantuxedo_big_file_uploads.php:136
authwp_ajax_bfu_upload_dismisstuxedo_big_file_uploads.php:137
authwp_ajax_bfu_upgrade_dismisstuxedo_big_file_uploads.php:138
authwp_ajax_bfu_subscribe_dismisstuxedo_big_file_uploads.php:139
WordPress Hooks 17
actionadmin_noticesclasses\class-promo-notice.php:8
actioninittuxedo_big_file_uploads.php:107
actionadmin_noticestuxedo_big_file_uploads.php:108
filterplupload_inittuxedo_big_file_uploads.php:109
filterupload_post_paramstuxedo_big_file_uploads.php:110
filterplupload_default_settingstuxedo_big_file_uploads.php:111
filterplupload_default_paramstuxedo_big_file_uploads.php:112
filterupload_size_limittuxedo_big_file_uploads.php:113
actionpost-upload-uituxedo_big_file_uploads.php:116
actionenqueue_block_editor_assetstuxedo_big_file_uploads.php:117
filterblock_editor_settings_alltuxedo_big_file_uploads.php:118
actionadmin_menutuxedo_big_file_uploads.php:122
filterplugin_action_links_tuxedo-big-file-uploads/tuxedo_big_file_uploads.phptuxedo_big_file_uploads.php:123
actionnetwork_admin_menutuxedo_big_file_uploads.php:129
filternetwork_admin_plugin_action_links_tuxedo-big-file-uploads/tuxedo_big_file_uploads.phptuxedo_big_file_uploads.php:130
actionnetwork_admin_noticestuxedo_big_file_uploads.php:143
actionadmin_noticestuxedo_big_file_uploads.php:145
Maintenance & Trust

Big File Uploads – Increase Maximum File Upload Size Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 2, 2025
PHP min version5.6
Downloads1.2M

Community Trust

Rating98/100
Number of ratings380
Active installs100K
Developer Profile

Big File Uploads – Increase Maximum File Upload Size Developer Profile

Infinite Uploads

6 plugins · 101K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
18 days
View full developer profile
Detection Fingerprints

How We Detect Big File Uploads – Increase Maximum File Upload Size

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tuxedo-big-file-uploads/assets/js/bfu-gutenberg-block.js/wp-content/plugins/tuxedo-big-file-uploads/assets/js/bfu-admin-notices.js/wp-content/plugins/tuxedo-big-file-uploads/assets/js/bfu-admin-settings.js/wp-content/plugins/tuxedo-big-file-uploads/assets/css/bfu-admin-styles.css
Script Paths
/wp-content/plugins/tuxedo-big-file-uploads/assets/js/bfu-gutenberg-block.js/wp-content/plugins/tuxedo-big-file-uploads/assets/js/bfu-admin-notices.js/wp-content/plugins/tuxedo-big-file-uploads/assets/js/bfu-admin-settings.js
Version Parameters
tuxedo-big-file-uploads/assets/js/bfu-gutenberg-block.js?ver=tuxedo-big-file-uploads/assets/js/bfu-admin-notices.js?ver=tuxedo-big-file-uploads/assets/js/bfu-admin-settings.js?ver=tuxedo-big-file-uploads/assets/css/bfu-admin-styles.css?ver=

HTML / DOM Fingerprints

CSS Classes
bfu-noticebfu-review-noticebfu-upgrade-noticebfu-upgrade-messagebfu-buttonbfu-pro-featurebfu-settings-fieldbfu-admin-notice-dismiss+2 more
HTML Comments
Big File Uploads ManagerBig File Uploads SettingsBig File Uploads Admin NoticesBig File Uploads Gutenberg Block Notice
Data Attributes
data-bfu-dismissdata-bfu-subscribe-dismissdata-bfu-upgrade-dismissdata-bfu-review-dismiss
JS Globals
bfu_admin_paramsbfu_gutenberg_params
REST Endpoints
/wp-json/bfu/v1/scan/wp-json/bfu/v1/dismiss/wp-json/bfu/v1/upgrade/dismiss/wp-json/bfu/v1/subscribe/dismiss
FAQ

Frequently Asked Questions about Big File Uploads – Increase Maximum File Upload Size