Impact
The Ally – Web Accessibility & Usability plugin contains a flaw where the enable_unfiltered_files_upload function lacks proper nonce validation. An attacker can create a forged request that, when a site administrator clicks a link while logged in, toggles the unfiltered upload setting to true and adds SVG files to the list of allowed file types. With this change, an administrator could unknowingly upload arbitrary files that are not normally permitted.
Affected Systems
WordPress sites that run the Ally – Web Accessibility & Usability plugin version 3.8.0 or earlier. Any site where the plugin is installed and an authenticated administrator is present is vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation at the time of analysis. The vulnerability is not yet listed in CISA's KEV catalog. Exploitation would require an attacker to lure an administrator into clicking a crafted URL while logged in, after which the attacker can enable unfiltered uploads and potentially upload malicious files.
OpenCVE Enrichment