CVE-2026-85576 Overview
CVE-2026-85576 affects the All in One Files Upload WordPress plugin in versions prior to 2.0.17. The plugin fails to perform capability checks and does not verify request authenticity when saving its settings. Any authenticated user, including a low-privileged subscriber, can modify plugin configuration. The flaw combines missing authorization [CWE-862] with missing Cross-Site Request Forgery (CSRF) protection [CWE-352].
Critical Impact
Authenticated subscribers can alter plugin settings that govern file upload behavior, expanding attack surface for follow-on exploitation.
Affected Products
- All in One Files Upload WordPress plugin versions before 2.0.17
- WordPress sites permitting subscriber-level registration
- Any WordPress deployment with the vulnerable plugin active
Discovery Timeline
- 2026-09-30 - CVE-2026-85576 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-85576
Vulnerability Analysis
The All in One Files Upload plugin exposes a settings save handler that neither validates the caller's WordPress capabilities nor verifies a nonce. WordPress plugins typically gate administrative actions with current_user_can() checks and check_admin_referer() or wp_verify_nonce() calls. Neither guard is present in the vulnerable code path.
An authenticated attacker with the lowest privilege role, subscriber, can submit a crafted request to the settings endpoint. The plugin persists the submitted values as the new configuration. This grants low-privileged users control over settings normally reserved for administrators.
Root Cause
The root cause is a broken access control pattern in the settings save routine. WordPress relies on plugin developers to enforce capability boundaries. The plugin invokes its settings persistence logic on any authenticated request, treating authentication as sufficient authorization. Absence of a nonce check further permits CSRF-style abuse against higher-privileged users.
Attack Vector
Exploitation requires a valid WordPress account. On sites that allow open registration, an attacker registers a subscriber account and issues a POST request to the plugin's settings handler with attacker-chosen values. The plugin accepts and stores the settings. Modified upload configuration can enable subsequent attacks such as unrestricted file uploads or malicious content placement, depending on which options the plugin exposes. Refer to the WPScan Vulnerability Report for technical details.
Detection Methods for CVE-2026-85576
Indicators of Compromise
- Unexpected modifications to All in One Files Upload plugin settings in the wp_options table
- POST requests to the plugin's settings endpoint originating from subscriber-level session cookies
- New or altered file upload directories, allowed MIME types, or extension allowlists in plugin configuration
- Uploaded files with executable extensions in plugin-managed upload directories
Detection Strategies
- Audit the WordPress wp_options records associated with the plugin against a known-good baseline
- Review web server access logs for POST requests to plugin admin-ajax or settings paths from non-administrator users
- Inspect user registration logs for unusual subscriber account creation followed by administrative-style POSTs
Monitoring Recommendations
- Enable WordPress audit logging to capture settings changes and correlate them with the acting user role
- Alert on any file upload with a script-capable extension in plugin-managed directories
- Track version inventory of installed plugins and flag hosts running versions prior to 2.0.17
How to Mitigate CVE-2026-85576
Immediate Actions Required
- Update the All in One Files Upload plugin to version 2.0.17 or later on every WordPress site where it is installed
- Disable and remove the plugin if an update is not immediately feasible
- Review and revert any unauthorized settings changes performed while the vulnerable version was active
- Audit subscriber accounts created recently and remove suspicious entries
Patch Information
Upgrade to All in One Files Upload version 2.0.17, which introduces capability checks and nonce verification on the settings save handler. Consult the WPScan Vulnerability Report for the corrected version reference.
Workarounds
- Disable open user registration in WordPress general settings to prevent attacker-created subscriber accounts
- Restrict access to /wp-admin/admin-ajax.php and plugin settings endpoints via web application firewall rules for non-administrator roles
- Temporarily deactivate the plugin until the patched version is deployed
# Update the plugin via WP-CLI
wp plugin update all-in-one-files-upload --version=2.0.17
# Verify installed version
wp plugin get all-in-one-files-upload --field=version
# Disable open registration as a hardening step
wp option update users_can_register 0
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
