WPHizmet

Eklenti güvenlik geçmişi

Iptanus File Upload güvenlik açıkları

ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) Iptanus File Upload eklentisi için 2 açık kaydı bulunuyor; en yenisi 9 Ağustos 2026 tarihli. Bunların 1 tanesi kritik veya yüksek önemde, 1 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 5.2.0.

Toplam kayıt
2
Kritik veya yüksek
1
Oturumsuz istismar
1
Son kayıt
9 Ağustos 2026

Bilinen açık kayıtları

En yeniden eskiye. Her kaydın özgün metni NVD’de.

  • CVE-2026-17044Yüksek · 8,69 Ağustos 2026

    SQL enjeksiyonu

    Etkilenen sürümler: 5.1.8 öncesi · Oturum açmadan istismar edilebilir

    The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users.

  • CVE-2025-15546Orta · 5,414 Haziran 2026

    güvenlik

    Etkilenen sürümler: 5.1.7 öncesi

    The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the file existence check and the actual file write operation, an authenticated attacker can overwrite files uploaded by other users.

Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 7 Ekim 2026 itibarıyla.