Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.6
CVE-2026-17044: WordPress File Upload Plugin - Unauthenticated SQL Injection
CVE-2026-17044 · published 26 days ago
Summary
The WordPress File Upload plugin, used in some websites, has a security flaw that could allow hackers to access sensitive data without a password. This affects sites using an outdated version of the plugin. Update to the latest version to fix the issue.
What to do
- Update unknown iptanus file upload to version 5.1.8 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| unknown | iptanus file upload | < 5.1.8 |
Original advisory text
WordPress File Upload < 5.1.8 - Unauthenticated SQL Injection via uniqueuploadid
The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users.
References
- https://wpscan.com/vulnerability/364c99a4-4ce9-4e5f-bccc-2b4081e4031d/ exploit vdb-entry technical-description
Severity
8.6
High
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
Timeline
Published9 Aug 2026
Updated29 Aug 2026
First seen9 Aug 2026
Monitor software like this
Free during beta