CVE-2026-17044 PUBLISHED

WordPress File Upload < 5.1.8 - Unauthenticated SQL Injection via uniqueuploadid

Assigner: WPScan
Reserved: 24.07.2026 Published: 09.08.2026 Updated: 09.08.2026

The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users.

Product Status

Vendor Unknown
Product Iptanus File Upload
Versions Default: unaffected
  • affected from 0 to 5.1.8 (excl.)

Credits

  • Pedro Pinho finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE