Authorization Bypass Vulnerability in Foxtool All-in-One Plugin for WordPress
CVE-2026-18317
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 September 2026
What is CVE-2026-18317?
The Foxtool All-in-One plugin for WordPress is vulnerable to an authorization bypass that affects all versions up to and including 2.5.3. This vulnerability arises from inadequate checks to verify user permissions, enabling authenticated users with subscriber-level access and above to modify critical subkeys within the foxtool_settings option. This includes the potential to enable site-wide SVG uploads by changing the media-up3 key. The improper handling of SVG files can lead to stored cross-site scripting, posing significant security risks to the website.
Affected Version(s)
Foxtool All-in-One: Contact chat button, Custom login, Media optimize images 0 <= 2.5.3