CVE-2026-17044: WordPress File Upload < 5.1.8 - Unauthenticated SQL Injection via uniqueuploadid
Published Aug 9, 2026
·Updated
The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users.
Affected Software
1 affected component
Iptanus WordPress File Upload<5.1.8
Event History
Aug 9, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness