MEDIUM
foxtheme
CVE published 2026-09-18
CVE-2026-18317
The Foxtool All-in-One plugin for WordPress has an authorization bypass vulnerability in versions up to 2.5.3. This allows authenticated attackers with subscriber-level access to modify arbitrary subkeys of the foxtool_settings option, including enabling site-wide SVG uploads. Defenders should assess exposure and prioritize verification and remediation to prevent potential stored cross-site scripting via [truncated]