Skip to main content
Vulnerability Database/CVE-2026-85573

CVE-2026-85573: WordPress File Upload Plugin RCE Vulnerability

CVE-2026-85573 is a remote code execution flaw in the All in One Files Upload WordPress plugin that allows unauthenticated attackers to upload malicious SVG files. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-85573 Overview

CVE-2026-85573 affects the All in One Files Upload WordPress plugin in versions before 2.0.17. The plugin adds Scalable Vector Graphics (SVG) to the site's allowed upload types without sanitising uploaded files or verifying the authenticity of public upload requests. Unauthenticated attackers can upload SVG files containing active content such as embedded JavaScript. When a victim opens the file, the script runs in the origin of the affected WordPress site, enabling stored Cross-Site Scripting (XSS) [CWE-79] and Cross-Site Request Forgery (CSRF) [CWE-352] conditions.

Critical Impact

Unauthenticated attackers can store SVG payloads that execute JavaScript in the site's origin, enabling session theft, administrative account takeover, and site defacement.

Affected Products

  • All in One Files Upload WordPress plugin versions prior to 2.0.17
  • WordPress installations with the plugin active and public upload endpoints reachable
  • Any site relying on the plugin's default upload type configuration

Discovery Timeline

  • 2026-09-30 - CVE CVE-2026-85573 published to the National Vulnerability Database (NVD)
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-85573

Vulnerability Analysis

The plugin extends WordPress's list of permitted MIME types to include SVG. SVG is an XML-based image format that can embed <script> elements, event handlers, and foreign objects. When a browser renders such a file directly, it executes any embedded JavaScript in the context of the hosting origin.

The plugin does not sanitise uploaded SVG content to strip active elements, and it does not verify the authenticity of upload requests through nonces or capability checks. Public upload endpoints therefore accept anonymous submissions. An attacker who convinces or coerces a victim, including an authenticated administrator, to open the stored file gains script execution against the WordPress origin.

Root Cause

The root cause is a combination of missing input sanitisation on SVG file contents and missing authenticity verification on public upload requests. The plugin trusts the file type check and permits raw XML with executable content to persist on disk and be served under the site's domain.

Attack Vector

An unauthenticated remote attacker submits a crafted SVG containing JavaScript, for example within a <script> block or an onload attribute on the root <svg> element, to the plugin's public upload handler. The file is stored in the WordPress uploads directory. When any visitor, including a logged-in administrator, navigates to the file's URL, the script executes in the site's origin. The attacker can then read cookies not marked HttpOnly, issue authenticated requests on behalf of the victim, or modify DOM content.

No verified exploit code is published in the referenced advisory. See the WPScan Vulnerability Report for advisory-level technical detail.

Detection Methods for CVE-2026-85573

Indicators of Compromise

  • SVG files in wp-content/uploads/ containing <script> tags, on* event handlers, <foreignObject>, or javascript: URIs
  • Access log entries showing unauthenticated POST requests to the plugin's upload endpoints followed by GET requests to newly created SVG paths from external IP addresses
  • Unexpected administrator actions, new privileged users, or plugin/theme edits following an administrator's visit to an uploaded SVG URL

Detection Strategies

  • Inventory installed WordPress plugins and flag any all-in-one-files-upload installation with a version below 2.0.17
  • Scan the uploads directory for SVG files and parse them for script elements or event handler attributes using an XML-aware parser
  • Correlate web server logs for anonymous file uploads immediately followed by SVG retrievals from different source addresses

Monitoring Recommendations

  • Alert on creation of .svg files in WordPress uploads directories on production hosts
  • Monitor for unauthenticated HTTP requests to plugin upload endpoints and rate-limit or block at the WAF
  • Track administrator session activity for anomalous API calls occurring shortly after opening a media file

How to Mitigate CVE-2026-85573

Immediate Actions Required

  • Update the All in One Files Upload plugin to version 2.0.17 or later
  • Audit wp-content/uploads/ for existing SVG files and remove or quarantine any containing active content
  • Rotate WordPress administrator credentials and invalidate active sessions if suspicious uploads are found

Patch Information

The vendor addressed the issue in version 2.0.17 of the All in One Files Upload plugin. Refer to the WPScan Vulnerability Report for the fix reference.

Workarounds

  • Deactivate the plugin until the patched version is deployed
  • Remove SVG from allowed upload MIME types by filtering upload_mimes in a mu-plugin
  • Serve wp-content/uploads/ with a Content-Security-Policy that forbids inline script and with Content-Disposition: attachment for SVG responses
  • Place a Web Application Firewall (WAF) rule in front of the plugin's public upload endpoint to require authenticated sessions
bash
# Example: block SVG uploads via WordPress filter (mu-plugin)
add_filter('upload_mimes', function($mimes) {
    unset($mimes['svg']);
    unset($mimes['svgz']);
    return $mimes;
});

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.