๐Ÿ” CVE Alert

CVE-2026-85576

UNKNOWN 0.0

All in One Files Upload for WooCommerce < 2.0.17 - Subscriber+ Arbitrary Plugin Settings Update

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, when saving its settings, allowing any authenticated user, such as a subscriber, to change them.

Vendor unknown
Product all in one files upload
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown all in one files upload

Be the first to know when new unknown vulnerabilities affecting unknown all in one files upload are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / All in One Files Upload
0 < 2.0.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/5c4546f4-fa6f-47a5-9d2b-9493d34dc13d/

Credits

Erwan LR (WPScan) WPScan