Beveiligingsadvies

CVE-2025-15546

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-14 06:00:03
Laatst bijgewerkt 2026-07-06 14:38:27
Toegewezen door WPScan
CVSS-score 5.4
Status PUBLISHED

Beschrijving

The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the file existence check and the actual file write operation, an authenticated attacker can overwrite files uploaded by other users.