The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, when saving its settings, allowing any authenticated user, such as a subscriber, to change them.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 30 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, when saving its settings, allowing any authenticated user, such as a subscriber, to change them. | |
| Title | All in One Files Upload for WooCommerce < 2.0.17 - Subscriber+ Arbitrary Plugin Settings Update | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-30T06:00:22.290Z
Reserved: 2026-09-04T10:56:03.374Z
Link: CVE-2026-85576
No data.
Status : Received
Published: 2026-09-30T06:17:06.793
Modified: 2026-09-30T06:17:06.793
Link: CVE-2026-85576
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.