Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xwgf-8969-9fm2

Опубликовано: 14 июн. 2026
Источник: github
Github: Не прошло ревью

Описание

The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the file existence check and the actual file write operation, an authenticated attacker can overwrite files uploaded by other users.

The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the file existence check and the actual file write operation, an authenticated attacker can overwrite files uploaded by other users.

EPSS

Процентиль: 4%
0.00148
Низкий

Связанные уязвимости

nvd
7 дней назад

The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the file existence check and the actual file write operation, an authenticated attacker can overwrite files uploaded by other users.

EPSS

Процентиль: 4%
0.00148
Низкий