CVE-2026-85576: All in One Files Upload for WooCommerce < 2.0.17 - Subscriber+ Arbitrary Plugin Settings Update
The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, when saving its settings, allowing any authenticated user, such as a subscriber, to change them.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
All in One Files Upload for WooCommerceto a version that resolves this vulnerability.Fixed in 2.0.17
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user can exploit it, including users with only the Subscriber role. The attacker must be able to send a request while logged in.
Are default installations affected?
The issue is caused by missing capability and request-authenticity checks when plugin settings are saved. Therefore, an affected version can be exposed wherever authenticated users can access the relevant settings-saving request, including low-privilege accounts.
How can I determine whether my site is affected?
Check the installed version of All in One Files Upload for WooCommerce. Versions earlier than 2.0.17 are affected.
What should I do if I cannot update immediately?
Restrict or remove low-privilege authenticated accounts where possible, since Subscribers can exploit the issue. Review the plugin's settings for unauthorized changes and limit access to the affected site until an update can be applied.