Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-17044: WordPress File Upload Plugin - Unauthenticated SQL Injection

CVE-2026-17044 · published 26 days ago
Summary

The WordPress File Upload plugin, used in some websites, has a security flaw that could allow hackers to access sensitive data without a password. This affects sites using an outdated version of the plugin. Update to the latest version to fix the issue.

What to do
  • Update unknown iptanus file upload to version 5.1.8 or later.
Affected software
VendorProductAffected versions
unknown iptanus file upload < 5.1.8
Original advisory text
WordPress File Upload < 5.1.8 - Unauthenticated SQL Injection via uniqueuploadid
The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users.
References
Severity
8.6 High
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
Timeline
Published9 Aug 2026
Updated29 Aug 2026
First seen9 Aug 2026
Sources
CVE-2026-17044 · MITRE
Monitor software like this
Free during beta