CVE-2025-15546

Published: Giu 14, 2026 Last Modified: Giu 14, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to 'maintain both.' Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the file existence check and the actual file write operation, an authenticated attacker can overwrite files uploaded by other users.

https://wpscan.com/vulnerability/06e33418-1644-49a1-b012-122046604109/