๐Ÿ” CVE Alert

CVE-2026-85573

UNKNOWN 0.0

All in One Files Upload for WooCommerce 2.0.3 - 2.0.16 - Unauthenticated Stored XSS via SVG Upload

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim opens them.

Vendor unknown
Product all in one files upload
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown all in one files upload

Be the first to know when new unknown vulnerabilities affecting unknown all in one files upload are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / All in One Files Upload
2.0.3 < 2.0.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/0f7f1f25-02e2-49b5-9690-31857e9e6bda/

Credits

Mike Gozdiskowski WPScan