VYPR

Iptanus File Upload

by WordPress

CVEs (2)

  • CVE-2018-9172MedApr 1, 2018
    risk 0.38cvss 5.4epss 0.03

    The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.

  • CVE-2025-15546Jun 14, 2026
    risk 0.00cvss epss 0.00

    The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the file existence check and the actual file…