Back

HIGH

All in One Files Upload for WooCommerce 2.0.3 - 2.0.16 - Unauthenticated Stored XSS via SVG Upload

Published Sep 30, 2026

Description

The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim opens them.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Sep 30, 2026
Updated Sep 30, 2026
Reserved Sep 4, 2026
CISA Vulnrichment
Updated Sep 30, 2026
NVD
Status Received
Modified Sep 30, 2026
Red Hat
Severity n/a
Public date n/a