CVE-2026-85576
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Sep 30, 2026
Vendor
unknown
Description
The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, when saving its settings, allowing any authenticated user, such as a subscriber, to change them.