---
id: CVE-2026-85576
title: >-
  The All in One Files Upload WordPress plugin before 2.0.17 does not have any
  capability check, and does not verify the authenticity of the request, when
  saving its settings, allowing any authenticated user, such as a subscriber, to
  chang…
summary: >-
  The All in One Files Upload WordPress plugin before 2.0.17 does not have any
  capability check, and does not verify the authenticity of the request, when
  saving its settings, allowing any authenticated user, such as a subscriber, to
  chang…
severity: none
cwe:
  - CWE-862
product: All in One Files Upload
affected:
  - all_in_one_files_upload < 2.0.17
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T06:17:06.793'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85576'
references:
  - url: 'https://wpscan.com/vulnerability/5c4546f4-fa6f-47a5-9d2b-9493d34dc13d/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T06:58:55.553Z'
---

## Overview

The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, when saving its settings, allowing any authenticated user, such as a subscriber, to change them.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
