CVE-2026-85573 Overview
CVE-2026-85573 affects the All in One Files Upload WordPress plugin in versions before 2.0.17. The plugin adds Scalable Vector Graphics (SVG) to the site's allowed upload types without sanitising uploaded files or verifying the authenticity of public upload requests. Unauthenticated attackers can upload SVG files containing active content such as embedded JavaScript. When a victim opens the file, the script runs in the origin of the affected WordPress site, enabling stored Cross-Site Scripting (XSS) [CWE-79] and Cross-Site Request Forgery (CSRF) [CWE-352] conditions.
Critical Impact
Unauthenticated attackers can store SVG payloads that execute JavaScript in the site's origin, enabling session theft, administrative account takeover, and site defacement.
Affected Products
- All in One Files Upload WordPress plugin versions prior to 2.0.17
- WordPress installations with the plugin active and public upload endpoints reachable
- Any site relying on the plugin's default upload type configuration
Discovery Timeline
- 2026-09-30 - CVE CVE-2026-85573 published to the National Vulnerability Database (NVD)
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-85573
Vulnerability Analysis
The plugin extends WordPress's list of permitted MIME types to include SVG. SVG is an XML-based image format that can embed <script> elements, event handlers, and foreign objects. When a browser renders such a file directly, it executes any embedded JavaScript in the context of the hosting origin.
The plugin does not sanitise uploaded SVG content to strip active elements, and it does not verify the authenticity of upload requests through nonces or capability checks. Public upload endpoints therefore accept anonymous submissions. An attacker who convinces or coerces a victim, including an authenticated administrator, to open the stored file gains script execution against the WordPress origin.
Root Cause
The root cause is a combination of missing input sanitisation on SVG file contents and missing authenticity verification on public upload requests. The plugin trusts the file type check and permits raw XML with executable content to persist on disk and be served under the site's domain.
Attack Vector
An unauthenticated remote attacker submits a crafted SVG containing JavaScript, for example within a <script> block or an onload attribute on the root <svg> element, to the plugin's public upload handler. The file is stored in the WordPress uploads directory. When any visitor, including a logged-in administrator, navigates to the file's URL, the script executes in the site's origin. The attacker can then read cookies not marked HttpOnly, issue authenticated requests on behalf of the victim, or modify DOM content.
No verified exploit code is published in the referenced advisory. See the WPScan Vulnerability Report for advisory-level technical detail.
Detection Methods for CVE-2026-85573
Indicators of Compromise
- SVG files in wp-content/uploads/ containing <script> tags, on* event handlers, <foreignObject>, or javascript: URIs
- Access log entries showing unauthenticated POST requests to the plugin's upload endpoints followed by GET requests to newly created SVG paths from external IP addresses
- Unexpected administrator actions, new privileged users, or plugin/theme edits following an administrator's visit to an uploaded SVG URL
Detection Strategies
- Inventory installed WordPress plugins and flag any all-in-one-files-upload installation with a version below 2.0.17
- Scan the uploads directory for SVG files and parse them for script elements or event handler attributes using an XML-aware parser
- Correlate web server logs for anonymous file uploads immediately followed by SVG retrievals from different source addresses
Monitoring Recommendations
- Alert on creation of .svg files in WordPress uploads directories on production hosts
- Monitor for unauthenticated HTTP requests to plugin upload endpoints and rate-limit or block at the WAF
- Track administrator session activity for anomalous API calls occurring shortly after opening a media file
How to Mitigate CVE-2026-85573
Immediate Actions Required
- Update the All in One Files Upload plugin to version 2.0.17 or later
- Audit wp-content/uploads/ for existing SVG files and remove or quarantine any containing active content
- Rotate WordPress administrator credentials and invalidate active sessions if suspicious uploads are found
Patch Information
The vendor addressed the issue in version 2.0.17 of the All in One Files Upload plugin. Refer to the WPScan Vulnerability Report for the fix reference.
Workarounds
- Deactivate the plugin until the patched version is deployed
- Remove SVG from allowed upload MIME types by filtering upload_mimes in a mu-plugin
- Serve wp-content/uploads/ with a Content-Security-Policy that forbids inline script and with Content-Disposition: attachment for SVG responses
- Place a Web Application Firewall (WAF) rule in front of the plugin's public upload endpoint to require authenticated sessions
# Example: block SVG uploads via WordPress filter (mu-plugin)
add_filter('upload_mimes', function($mimes) {
unset($mimes['svg']);
unset($mimes['svgz']);
return $mimes;
});
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
