Executive brief
The Iptanus File Upload plugin for WordPress, which allows users to upload files to a website, contains a flaw in how it handles duplicate files. When configured to keep both the old and new versions of a file, a timing error allows an attacker to bypass safety checks. This could allow an authorized user to accidentally or intentionally overwrite files uploaded by other users, potentially leading to data loss or unauthorized modification of site content.
Technical details
A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the Iptanus File Upload (wp-file-upload) plugin for WordPress before version 5.1.7. The vulnerability occurs when the 'duplicatepolicy' setting is set to 'maintain both'. There is a window of time between the plugin checking for a file's existence and performing the write operation; by sending multiple concurrent upload requests, an authenticated attacker can exploit this gap to overwrite existing files instead of creating a unique version. This bypasses the intended file-naming logic designed to prevent data loss. The issue is fixed in version 5.1.7.
Affected products
- Iptanus File Upload (wp-file-upload) < 5.1.7
Timeline
- 2026-02-24: other: Vulnerability added to WPScan database
- 2026-05-24: disclosed: Public disclosure
- 2026-06-14: advisory: NVD publication date