Skip to main content
Vulnerability Database/CVE-2026-85576

CVE-2026-85576: WordPress All in One Files Upload Auth Bypass

CVE-2026-85576 is an authentication bypass flaw in the All in One Files Upload WordPress plugin that allows any authenticated user to modify plugin settings without proper authorization. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-85576 Overview

CVE-2026-85576 affects the All in One Files Upload WordPress plugin in versions prior to 2.0.17. The plugin fails to perform capability checks and does not verify request authenticity when saving its settings. Any authenticated user, including a low-privileged subscriber, can modify plugin configuration. The flaw combines missing authorization [CWE-862] with missing Cross-Site Request Forgery (CSRF) protection [CWE-352].

Critical Impact

Authenticated subscribers can alter plugin settings that govern file upload behavior, expanding attack surface for follow-on exploitation.

Affected Products

  • All in One Files Upload WordPress plugin versions before 2.0.17
  • WordPress sites permitting subscriber-level registration
  • Any WordPress deployment with the vulnerable plugin active

Discovery Timeline

  • 2026-09-30 - CVE-2026-85576 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-85576

Vulnerability Analysis

The All in One Files Upload plugin exposes a settings save handler that neither validates the caller's WordPress capabilities nor verifies a nonce. WordPress plugins typically gate administrative actions with current_user_can() checks and check_admin_referer() or wp_verify_nonce() calls. Neither guard is present in the vulnerable code path.

An authenticated attacker with the lowest privilege role, subscriber, can submit a crafted request to the settings endpoint. The plugin persists the submitted values as the new configuration. This grants low-privileged users control over settings normally reserved for administrators.

Root Cause

The root cause is a broken access control pattern in the settings save routine. WordPress relies on plugin developers to enforce capability boundaries. The plugin invokes its settings persistence logic on any authenticated request, treating authentication as sufficient authorization. Absence of a nonce check further permits CSRF-style abuse against higher-privileged users.

Attack Vector

Exploitation requires a valid WordPress account. On sites that allow open registration, an attacker registers a subscriber account and issues a POST request to the plugin's settings handler with attacker-chosen values. The plugin accepts and stores the settings. Modified upload configuration can enable subsequent attacks such as unrestricted file uploads or malicious content placement, depending on which options the plugin exposes. Refer to the WPScan Vulnerability Report for technical details.

Detection Methods for CVE-2026-85576

Indicators of Compromise

  • Unexpected modifications to All in One Files Upload plugin settings in the wp_options table
  • POST requests to the plugin's settings endpoint originating from subscriber-level session cookies
  • New or altered file upload directories, allowed MIME types, or extension allowlists in plugin configuration
  • Uploaded files with executable extensions in plugin-managed upload directories

Detection Strategies

  • Audit the WordPress wp_options records associated with the plugin against a known-good baseline
  • Review web server access logs for POST requests to plugin admin-ajax or settings paths from non-administrator users
  • Inspect user registration logs for unusual subscriber account creation followed by administrative-style POSTs

Monitoring Recommendations

  • Enable WordPress audit logging to capture settings changes and correlate them with the acting user role
  • Alert on any file upload with a script-capable extension in plugin-managed directories
  • Track version inventory of installed plugins and flag hosts running versions prior to 2.0.17

How to Mitigate CVE-2026-85576

Immediate Actions Required

  • Update the All in One Files Upload plugin to version 2.0.17 or later on every WordPress site where it is installed
  • Disable and remove the plugin if an update is not immediately feasible
  • Review and revert any unauthorized settings changes performed while the vulnerable version was active
  • Audit subscriber accounts created recently and remove suspicious entries

Patch Information

Upgrade to All in One Files Upload version 2.0.17, which introduces capability checks and nonce verification on the settings save handler. Consult the WPScan Vulnerability Report for the corrected version reference.

Workarounds

  • Disable open user registration in WordPress general settings to prevent attacker-created subscriber accounts
  • Restrict access to /wp-admin/admin-ajax.php and plugin settings endpoints via web application firewall rules for non-administrator roles
  • Temporarily deactivate the plugin until the patched version is deployed
bash
# Update the plugin via WP-CLI
wp plugin update all-in-one-files-upload --version=2.0.17

# Verify installed version
wp plugin get all-in-one-files-upload --field=version

# Disable open registration as a hardening step
wp option update users_can_register 0

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.