plugin

File Manager Advanced Vulnerabilities

23 known security issues reported for the File Manager Advanced WordPress plugin. Most recent disclosed Aug 17, 2026.

6 high 7 medium

Running File Manager Advanced on your site? Check whether your installed version is affected.

Scan your site free

Advanced File Manager <= 5.4.12 - Missing Authorization

medium

The Advanced File Manager plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 5.4.12. This is due to a missing capability check on a function. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 5.4.12
Fixed in:
5.4.13
Disclosed:
Aug 17, 2026

CVE-2026-11565 on NVD →

Advanced File Manager <= 5.4.12 - Reflected Cross-Site Scripting via postMessage 'soundFile' Parameter

medium

The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'soundFile' parameter in all versions up to, and including, 5.4.12 due to insufficient input sanitization and output escaping. This makes it possible fo...

CVSS:
6.1
Affected:
up to 5.4.12
Fixed in:
5.4.13
Disclosed:
Aug 15, 2026

CVE-2026-15009 on NVD →

Multiple Plugins <= Multiple Versions - Authenticated Remote Code Execution

high

Multiple plugins and/or themes for WordPress are vulnerable to Remote Code Execution in various versions. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.

CVSS:
7.2
Affected:
up to 5.4.12
Fixed in:
5.4.12
Disclosed:
Jun 15, 2026

CVE-2026-6382 on NVD →

Multiple elFinder Plugins <= (Various Versions) - Directory Traversal to Arbitrary File Deletion

medium

Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerability requires a site owner to explicitly make an instance of the file man...

CVSS:
6.5
Affected:
up to 5.3.6
Fixed in:
5.4.0
Disclosed:
Aug 12, 2025

CVE-2025-0818 on NVD →

Advanced File Manager <= 5.3.1 - Missing Authorization to Notice Dismisaal

medium

The Advanced File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on a function in versions up to, and including, 5.3.1. This makes it possible for unauthenticated attackers to dismiss admin notices.

CVSS:
5.3
Affected:
up to 5.3.1
Fixed in:
5.3.2
Disclosed:
May 7, 2025

CVE-2025-47688 on NVD →

Advanced File Manager – Ultimate WP File Manager And Document Library Solution [file-manager-advanced] <= 5.3.1 (unfixed)

unknown

[en] Missing Authorization vulnerability in Saad Iqbal Advanced File Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Advanced File Manager: from n/a through 5.3.1.

Affected:
up to 5.3.1
Fix:
No patched version reported
Disclosed:
May 7, 2025

CVE-2025-47688 on NVD →

Advanced File Manager – Ultimate WP File Manager And Document Library Solution [file-manager-advanced] < 5.3.0

unknown

[en] The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.2.14 due to insufficient input sanitization and output escaping. This makes it possible for authenti...

Affected:
up to 5.3.0
Fixed in:
5.3.0
Disclosed:
Mar 7, 2025

CVE-2024-13805 on NVD →

Advanced File Manager <= 5.2.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload

medium

The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.2.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...

CVSS:
6.4
Affected:
up to 5.2.14
Fixed in:
5.3.0
Disclosed:
Mar 6, 2025

CVE-2024-13805 on NVD →

Advanced File Manager – Ultimate WP File Manager And Document Library Solution [file-manager-advanced] < 5.2.14

unknown

[en] The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fma_local_file_system' function in versions 5.2.12 to 5.2.13. This makes it possible for authenticated attackers, with Subscriber-level access and above and upload permissions granted...

Affected:
up to 5.2.14
Fixed in:
5.2.14
Disclosed:
Jan 17, 2025

CVE-2024-13333 on NVD →

Advanced File Manager 5.2.12 - 5.2.13 - Authenticated (Subscriber+) Arbitrary File Upload

high

The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fma_local_file_system' function in versions 5.2.12 to 5.2.13. This makes it possible for authenticated attackers, with Subscriber-level access and above and upload permissions granted by an...

CVSS:
7.5
Affected:
5.2.12 – 5.2.13
Fixed in:
5.2.14
Disclosed:
Jan 16, 2025

CVE-2024-13333 on NVD →

Advanced File Manager – Ultimate WP File Manager And Document Library Solution [file-manager-advanced] < 5.2.11

unknown

[en] The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.10. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted per...

Affected:
up to 5.2.11
Fixed in:
5.2.11
Disclosed:
Dec 3, 2024

CVE-2024-11391 on NVD →

Advanced File Manager <= 5.2.10 - Authenticated (Subscriber+) Arbitrary File Upload

high

The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.10. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissi...

CVSS:
7.5
Affected:
up to 5.2.10
Fixed in:
5.2.11
Disclosed:
Dec 2, 2024

CVE-2024-11391 on NVD →

Advanced File Manager – Ultimate WP File Manager And Document Library Solution [file-manager-advanced] < 5.2.9

unknown

[en] The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 5.2.8 via the 'fma_locale' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary files on the se...

Affected:
up to 5.2.9
Fixed in:
5.2.9
Disclosed:
Sep 26, 2024

CVE-2024-8704 on NVD →

Advanced File Manager – Ultimate WP File Manager And Document Library Solution [file-manager-advanced] < 5.2.9

unknown

[en] Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a lack of proper checks to ensure lower-privileged roles cannot upload .css and .js files to arbitrary directories. This makes it possible for authenticated attackers, with Subscriber-level access...

Affected:
up to 5.2.9
Fixed in:
5.2.9
Disclosed:
Sep 26, 2024

CVE-2024-8725 on NVD →

Advanced File Manager – Ultimate WP File Manager And Document Library Solution [file-manager-advanced] < 5.2.9

unknown

[en] The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to uplo...

Affected:
up to 5.2.9
Fixed in:
5.2.9
Disclosed:
Sep 26, 2024

CVE-2024-8126 on NVD →

Advanced File Manager <= 5.2.8 - Authenticated (Subscriber+) Arbitrary File Upload

high

The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to upload a...

CVSS:
7.5
Affected:
up to 5.2.8
Fixed in:
5.2.9
Disclosed:
Sep 25, 2024

CVE-2024-8126 on NVD →

Advanced File Manager <= 5.2.8 - Authenticated (Administrator+) Local JavaScript File Inclusion via fma_locale

high

The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 5.2.8 via the 'fma_locale' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary files on the server,...

CVSS:
7.2
Affected:
up to 5.2.8
Fixed in:
5.2.9
Disclosed:
Sep 25, 2024

CVE-2024-8704 on NVD →

Advanced File Manager <= 5.2.8 - Authenticated (Subscriber+) Limited File Upload

medium

Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a lack of proper checks to ensure lower-privileged roles cannot upload .css and .js files to arbitrary directories. This makes it possible for authenticated attackers, with Subscriber-level access and...

CVSS:
6.8
Affected:
up to 5.2.8
Fixed in:
5.2.9
Disclosed:
Sep 25, 2024

CVE-2024-8725 on NVD →

Advanced File Manager – Ultimate WP File Manager And Document Library Solution [file-manager-advanced] < 5.2.5

unknown

[en] The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.4 via the 'fma_local_file_system' function. This makes it possible for unauthenticated attackers to extract sensitive data including backups or other sensitive information if the...

Affected:
up to 5.2.5
Fixed in:
5.2.5
Disclosed:
Jun 29, 2024

CVE-2024-5598 on NVD →

Advanced File Manager <= 5.2.4 - Sensitive Information Exposure via Directory Listing

high

The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.4 via the 'fma_local_file_system' function. This makes it possible for unauthenticated attackers to extract sensitive data including backups or other sensitive information if the file...

CVSS:
7.5
Affected:
up to 5.2.4
Fixed in:
5.2.5
Disclosed:
Jun 28, 2024

CVE-2024-5598 on NVD →

Advanced File Manager – Ultimate WP File Manager And Document Library Solution [file-manager-advanced] < 5.1.1

unknown

[en] The Advanced File Manager WordPress plugin before 5.1.1 does not adequately authorize its usage on multisite installations, allowing site admin users to list and read arbitrary files and folders on the server.

Affected:
up to 5.1.1
Fixed in:
5.1.1
Disclosed:
Sep 4, 2023

CVE-2023-3814 on NVD →

Advanced File Manager <= 5.1 - Authenticated (Administrator+) Arbitrary File and Folder Access

medium

The Advanced File Managerplugin for WordPress is vulnerable to improper access control in versions up to, and including, 5.1. This makes it possible for authenticated attackers, with administrator-level permissions and above, to access the filesystem on multisite installations. This only affects multi-site installation...

CVSS:
6.6
Affected:
up to 5.1
Fixed in:
5.1.1
Disclosed:
Aug 14, 2023

CVE-2023-3814 on NVD →

Advanced File Manager – Ultimate WP File Manager And Document Library Solution [file-manager-advanced] < 5.4.0

unknown

Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerability requires a site owner to explicitly make an instance of the file man...

Affected:
up to 5.4.0
Fixed in:
5.4.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database