---
id: CVE-2026-85573
title: >-
  The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the
  site's allowed upload types and does not sanitise uploaded files or verify the
  authenticity of its public upload requests, allowing unauthenticated users to
  store…
summary: >-
  The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the
  site's allowed upload types and does not sanitise uploaded files or verify the
  authenticity of its public upload requests, allowing unauthenticated users to
  store…
severity: none
cwe:
  - CWE-79
product: All in One Files Upload
affected:
  - all_in_one_files_upload >= 2.0.3 < 2.0.17
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T06:17:06.503'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85573'
references:
  - url: 'https://wpscan.com/vulnerability/0f7f1f25-02e2-49b5-9690-31857e9e6bda/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T06:58:55.553Z'
---

## Overview

The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim opens them.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
