CVE-2026-17044: WordPress File Upload < 5.1.8 - Unauthenticated SQL Injection via uniqueuploadid
Published Aug 9, 2026
·Updated
The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users.
Affected Software
1 affected component
Iptanus WordPress File Upload<5.1.8
Event History
Aug 9, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:18 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-17044?
CVE-2026-17044 has a risk severity rating of 80, indicating a high level of concern.
2
How do I fix CVE-2026-17044?
To fix CVE-2026-17044, upgrade the Iptanus File Upload plugin to version 5.1.8 or later.
3
Who is affected by CVE-2026-17044?
CVE-2026-17044 affects users of the Iptanus File Upload WordPress plugin prior to version 5.1.8.
4
What type of vulnerability is CVE-2026-17044?
CVE-2026-17044 is classified as an SQL Injection vulnerability.
5
Can CVE-2026-17044 be exploited by unauthenticated users?
Yes, CVE-2026-17044 can be exploited by unauthenticated users due to improper sanitization of parameters.