The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the file existence check and the actual file write operation, an authenticated attacker can overwrite files uploaded by other users.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 14 Jun 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-362 |
Sun, 14 Jun 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the file existence check and the actual file write operation, an authenticated attacker can overwrite files uploaded by other users. | |
| Title | Iptanus File Upload < 5.1.7 - File Overwrite via Race Condition | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-06-14T06:00:03.776Z
Reserved: 2026-01-26T14:42:55.951Z
Link: CVE-2025-15546
No data.
Status : Received
Published: 2026-06-14T08:16:17.040
Modified: 2026-06-14T08:16:17.040
Link: CVE-2025-15546
No data.
OpenCVE Enrichment
Updated: 2026-06-14T08:30:07Z
Weaknesses