Impact
The Foxtool All-in-One WordPress plugin contains an authorization bypass that allows any authenticated user with subscriber or higher privileges to modify arbitrary subkeys of the foxtool_settings option via the toggle_watermark AJAX action. The vulnerable "option_key" parameter accepts user-supplied values without proper access checks, enabling attackers to enable site-wide SVG uploads by toggling the media-up3 key. This change can lead to stored cross‑site scripting if malicious SVG files are uploaded.
Affected Systems
All versions of Foxtool All‑in‑One: Contact chat button, Custom login, Media optimize images up to and including 2.5.3 are affected. The vulnerability originates from the media.php file in the plugin’s code base. No specific WordPress core version is required, and the flaw exists on any site that has installed a vulnerable plugin instance.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of <1% implies a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further reducing its exposure risk. The attack requires only subscriber or higher access, which many sites grant to regular authors, meaning that the threat surface is significant for sites that provide subscriber roles. Nevertheless, because the flaw relies on adjusting plugin settings, an attacker must be able to interact with the backend AJAX endpoint, so the possibility for remote exploitation depends on having authenticated access.
OpenCVE Enrichment