What is CVE-2026-17044?
This is an SQL injection vulnerability in the Iptanus File Upload WordPress plugin before version 5.1.8. The plugin fails to properly sanitize and escape a parameter before using it in an SQL statement, allowing unauthenticated attackers to manipulate the database. Updating the plugin to at least version 5.1.8 is recommended.
Azərbaycanca: Bu, Iptanus File Upload WordPress plaginində (5.1.8-dən əvvəlki versiyalar) aşkarlanmış SQL injection zəifliyidir. Plagin bir parametri SQL sorğusunda istifadə etməzdən əvvəl düzgün təmizləmədiyi üçün autentifikasiya olunmamış istifadəçilər verilənlər bazasına müdaxilə edə bilər. Plagini ən azı 5.1.8 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which users can exploit the CVE-2026-17044 vulnerability in the Iptanus File Upload WordPress plugin?
Unauthenticated attackers can exploit this SQL injection vulnerability to manipulate the database.
To which version should the Iptanus File Upload plugin be updated to fix the CVE-2026-17044 vulnerability?
The plugin should be updated to at least version 5.1.8.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.