The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users.CreditsPedro PinhoWPScanReferenceshttps://wpscan.com/vulnerability/364c99a4-4ce9-4e5f-bccc-2b4081e4031d/