---
id: CVE-2026-18317
title: >-
  The Foxtool All-in-One: Contact chat button, Custom login, Media optimize
  images plugin for WordPress is vulnerable to authorization bypass in all
  versions up to, and including, 2.5.3
summary: >-
  The Foxtool All-in-One: Contact chat button, Custom login, Media optimize
  images plugin for WordPress is vulnerable to authorization bypass in all
  versions up to, and including, 2.5.3. This is due to the plugin not properly
  verifying tha…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
vendor: foxtheme
product: 'Foxtool All-in-One: Contact chat button, Custom login, Media optimize images'
affected:
  - >-
    foxtool_all-in-one_contact_chat_button_custom_login_media_optimize_images <=
    2.5.3
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T15:17:06.530'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18317'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/foxtool/tags/2.5.3/inc/media.php#L854
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/foxtool/tags/2.5.3/inc/media.php#L868
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/foxtool/tags/2.5.3/inc/media.php#L926
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&old=3659917%40foxtool&new=3659917%40foxtool
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/10864109-8155-414e-be96-58e4dc2401b1?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-18T14:36:58.378591Z'
epss: 0.00213
epssPercentile: 0.10289
ingestedAt: '2026-09-18T07:37:23.430Z'
---

## Overview

The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify arbitrary subkeys of the foxtool_settings option, including enabling site-wide SVG uploads by toggling the media-up3 key, which can facilitate stored cross-site scripting via malicious SVG files.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
