PatchSiren

foxtheme CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM foxtheme CVE published 2026-09-18

CVE-2026-18317

The Foxtool All-in-One plugin for WordPress has an authorization bypass vulnerability in versions up to 2.5.3. This allows authenticated attackers with subscriber-level access to modify arbitrary subkeys of the foxtool_settings option, including enabling site-wide SVG uploads. Defenders should assess exposure and prioritize verification and remediation to prevent potential stored cross-site scripting via [truncated]