CVE-2026-85576
All in One Files Upload for WooCommerce < 2.0.17 - Subscriber+ Arbitrary Plugin Settings Update
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, when saving its settings, allowing any authenticated user, such as a subscriber, to change them.
| Vendor | unknown |
| Product | all in one files upload |
| Published | Sep 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown all in one files upload
Be the first to know when new unknown vulnerabilities affecting unknown all in one files upload are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / All in One Files Upload
0 < 2.0.17
References
Credits
Erwan LR (WPScan) WPScan