HIGH 8.8 NVD

CVE-2026-85573

The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authen

The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim opens them.

References

Published: 2026-09-30 · Source: NVD · Feed updated: 2026-09-30
This high severity vulnerability with a CVSS score of 8.8 was published on 2026-09-30 via NVD.
vulnfeed aggregates 9449 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.