All In One Files Upload

WordPress plugin · all-in-one-files-upload · WordPress.org ↗
0
Critical
1
High
2
Known total
0
Unfixed
Running All In One Files Upload on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
HIGH
CVSS 8.8
All in One Files Upload for WooCommerce 2.0.3 - 2.0.16 - Unauthenticated Stored XSS via SVG Upload
CVE.org
>=2.0.3, <2.0.17 v2.0.17 CVE-2026-85573 Sep 30, 2026
MEDIUM
CVSS 4.3
All in One Files Upload for WooCommerce < 2.0.17 - Subscriber+ Arbitrary Plugin Settings Update
CVE.org
>=0, <2.0.17 v2.0.17 CVE-2026-85576 Sep 30, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.