OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-85573

HIGH · CVSS 8.8 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The All in One Files Upload plugin for WordPress prior to version 2.0.17 is vulnerable due to its lack of sanitization for uploaded SVG files and failure to verify the authenticity of public upload requests. This allows unauthenticated users to upload malicious files that can execute active content within the site's context, potentially leading to cross-site scripting (XSS) or other attacks. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-85573
Severity
HIGH
CVSS
8.8
EPSS
0.28%
WordPress

Original NVD Description

The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim opens them.