Why WordPress is a target
Almost every business has a website now, and content management systems are the reason even a small company can have a capable one at a sensible cost. WordPress is by a wide margin the most widely used of them — current usage figures put it well ahead of every other CMS, and it runs a large fraction of all websites.
That popularity makes it a standing target. Attackers go after WordPress sites to get at information they should not have, or simply to break things. Serious breaches have been traced back to sites left unpatched — reporting on the Panama Papers leak, for one, pointed at an out-of-date WordPress installation as the likely way in.
The risk comes from themes and plugins
WordPress itself, with its default theme, is soundly built. But nobody ships a site with only that: the reason WordPress won is the enormous range of themes and plugins that anyone can install in a few clicks. Any one of them can undermine your security — by leaving a back door open, or by ignoring the practices WordPress itself sets out.
File upload adds a risk of its own
Plenty of businesses depend on exchanging files with their customers, and WordPress has no upload facility of its own, so that means a plugin. It is also one of the riskier things a plugin can do: an upload form is a door into your server, and a plugin without proper defences leaves it ajar.
How the plugin handles it
Iptanus File Upload takes that seriously. We have written up, in detail, every measure the plugin takes and the threat each one answers.

