Executive brief
Foxtool is a WordPress plugin providing contact chat, custom login, and media optimization features. The plugin fails to properly verify user permissions, allowing authenticated subscribers to modify plugin settings—including enabling dangerous SVG uploads site-wide. Attackers can exploit this to upload malicious SVG files that execute scripts in users' browsers, compromising site visitors' data and sessions.
Technical details
The vulnerability is an authorization bypass in the foxtool_settings option handler, affecting all versions up to 2.5.3. Authenticated users with subscriber-level privileges or higher can modify arbitrary subkeys of foxtool_settings without proper capability checks, including the media-up3 flag that controls SVG uploads. The lack of authorization verification allows attackers to toggle this setting and upload malicious SVG files, leading to stored cross-site scripting (XSS) attacks. No patch information is currently available; administrators should monitor for updates from the plugin maintainers.
Affected products
- Foxtool All-in-One: Contact chat button, Custom login, Media optimize images up to and including 2.5.3
Timeline
- 2026-09-18: disclosed