CVE-2025-15546EPSS p4.3%
CVE-2025-15546CVE-2025-15546
Description
The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the file existence check and the actual file write operation, an authenticated attacker can overwrite files uploaded by other users.
Scoring
| EPSS | 0.15% probability of exploitation · percentile 4.3% · 2026-06-19T12:03:05Z |
| Last modified | 2026-06-15 |