CVE-2025-15546 | Iptanus File Upload < 5.1.7 - File Overwrite via Race Condition

The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the file existence check and the actual file write operation, an authenticated attacker can overwrite files uploaded by other users.

Published: 2026-06-14 Last update: 2026-06-15 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2025-15546 is rated Low Risk (4.5/100): low exploitation likelihood (EPSS 0.15%). Mandatory action: Low composite risk—no urgent action required; patch on your normal maintenance cycle and revisit priority if CVSS or EPSS increases.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2025-15546

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.01% 0.15% +0.14%
2 2026-06-14 0.01%

Full EPSS history (2 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2025-15546

CVSS metrics for this CVE.

No CVSS data in dataset for this CVE.

Weakness enumeration for CVE-2025-15546

GitHub Security Advisory for CVE-2025-15546

GHSA-xwgf-8969-9fm2 · Severity: unknown — The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling...

Affected software / configurations for CVE-2025-15546

Vendor Product Version Raw CPE
No affected products in dataset.

References for CVE-2025-15546

cvelogic Threat Intelligence