CyberRota Analysis
AI-GeneratedThe All in One Files Upload plugin for WordPress prior to version 2.0.17 is vulnerable due to its lack of sanitization for uploaded SVG files and failure to verify the authenticity of public upload requests. This allows unauthenticated users to upload malicious files that can execute active content within the site's context, potentially leading to cross-site scripting (XSS) or other attacks. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.
Original NVD Description
The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim opens them.