CVE-2025-10700 Details
Description
The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This is due to missing or incorrect nonce validation on the enable_unfiltered_files_upload function. This makes it possible for unauthenticated attackers to enable unfiltered file upload and add svg files to the upload list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Ally – Web Accessibility & Usability plugin for WordPress, affecting all versions through 3.8.0. The vulnerability arises from inadequate nonce validation in the 'enable_unfiltered_files_upload' function, allowing unauthenticated attackers to manipulate file upload settings. Exploitation requires tricking a site administrator into performing an action, such as clicking a link, which would then enable unfiltered file uploads and allow the addition of SVG files to the upload list.
Users are advised to update the Ally – Web Accessibility & Usability WordPress plugin to version 3.8.1 or a later patched version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 16, 2025CISA-ADP
Assessed Oct 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Pojo Accessibility Ally | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 16, 2025 | New CVE Received | [email protected] |
Volerion