Impact
The Iptanus File Upload plugin for WordPress contains a time-of-check to time-of-use race condition that occurs when the duplicatepolicy setting is configured to "maintain both." The race condition allows an authenticated attacker to overwrite files already uploaded by other users, potentially replacing legitimate content with malicious files. The flaw is categorized as CWE-362 and represents an integrity violation.
Affected Systems
WordPress installations that have the Iptanus File Upload plugin installed at a version earlier than 5.1.7 and that use the duplicatepolicy setting to keep both copies of a file are affected. Any authenticated user that can access the plugin’s upload interface may trigger the vulnerability.
Risk and Exploitability
Exploitation requires the attacker to have authenticated access to the WordPress site and to initiate the vulnerable upload flow. The CVSS score of 5.4 indicates moderate risk, while the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, further implying limited exploitation activity at present.
OpenCVE Enrichment