Authorization Bypass Vulnerability in Foxtool All-in-One Plugin for WordPress
CVE-2026-18317

4.3MEDIUM

What is CVE-2026-18317?

The Foxtool All-in-One plugin for WordPress is vulnerable to an authorization bypass that affects all versions up to and including 2.5.3. This vulnerability arises from inadequate checks to verify user permissions, enabling authenticated users with subscriber-level access and above to modify critical subkeys within the foxtool_settings option. This includes the potential to enable site-wide SVG uploads by changing the media-up3 key. The improper handling of SVG files can lead to stored cross-site scripting, posing significant security risks to the website.

Affected Version(s)

Foxtool All-in-One: Contact chat button, Custom login, Media optimize images 0 <= 2.5.3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.