Description
The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify arbitrary subkeys of the foxtool_settings option, including enabling site-wide SVG uploads by toggling the media-up3 key, which can facilitate stored cross-site scripting via malicious SVG files.
Published: 2026-09-18
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized configuration change leading to potential stored XSS
Action: Patch Immediately
AI Analysis

Impact

The Foxtool All-in-One WordPress plugin contains an authorization bypass that allows any authenticated user with subscriber or higher privileges to modify arbitrary subkeys of the foxtool_settings option via the toggle_watermark AJAX action. The vulnerable "option_key" parameter accepts user-supplied values without proper access checks, enabling attackers to enable site-wide SVG uploads by toggling the media-up3 key. This change can lead to stored cross‑site scripting if malicious SVG files are uploaded.

Affected Systems

All versions of Foxtool All‑in‑One: Contact chat button, Custom login, Media optimize images up to and including 2.5.3 are affected. The vulnerability originates from the media.php file in the plugin’s code base. No specific WordPress core version is required, and the flaw exists on any site that has installed a vulnerable plugin instance.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the EPSS score of <1% implies a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further reducing its exposure risk. The attack requires only subscriber or higher access, which many sites grant to regular authors, meaning that the threat surface is significant for sites that provide subscriber roles. Nevertheless, because the flaw relies on adjusting plugin settings, an attacker must be able to interact with the backend AJAX endpoint, so the possibility for remote exploitation depends on having authenticated access.

Generated by OpenCVE AI on September 19, 2026 at 20:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Foxtool All-in-One to the latest version that removes the vulnerability.
  • Restrict or remove subscriber-level access to the site’s backend, or enforce stricter role permissions using a role‑management plugin.
  • If an upgrade is not possible, disable or delete the vulnerable plugin from the site.
  • Monitor the plugin’s settings and file integrity for unauthorized changes.

Generated by OpenCVE AI on September 19, 2026 at 20:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Foxtheme
Foxtheme foxtool All-in-one: Contact Chat Button, Custom Login, Media Optimize Images
Wordpress
Wordpress wordpress
Vendors & Products Foxtheme
Foxtheme foxtool All-in-one: Contact Chat Button, Custom Login, Media Optimize Images
Wordpress
Wordpress wordpress

Fri, 18 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify arbitrary subkeys of the foxtool_settings option, including enabling site-wide SVG uploads by toggling the media-up3 key, which can facilitate stored cross-site scripting via malicious SVG files.
Title Foxtool All-in-One: Contact chat button, Custom login, Media optimize images <= 2.5.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Modification via 'option_key' Parameter of toggle_watermark AJAX Action
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Foxtheme Foxtool All-in-one: Contact Chat Button, Custom Login, Media Optimize Images
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-18T14:42:42.583Z

Reserved: 2026-07-29T18:20:35.807Z

Link: CVE-2026-18317

cve-icon Vulnrichment

Updated: 2026-09-18T14:36:59.941Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T07:16:49.800

Modified: 2026-09-18T15:17:06.530

Link: CVE-2026-18317

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:30:46Z

Weaknesses