Advanced File Manager <= 5.4.12 - Missing Authorization
medium
The Advanced File Manager plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 5.4.12. This is due to a missing capability check on a function. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 5.4.12
- Fixed in:
- 5.4.13
- Disclosed:
- Aug 17, 2026
CVE-2026-11565 on NVD →
Advanced File Manager <= 5.4.12 - Reflected Cross-Site Scripting via postMessage 'soundFile' Parameter
medium
The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'soundFile' parameter in all versions up to, and including, 5.4.12 due to insufficient input sanitization and output escaping. This makes it possible fo...
- CVSS:
- 6.1
- Affected:
- up to 5.4.12
- Fixed in:
- 5.4.13
- Disclosed:
- Aug 15, 2026
CVE-2026-15009 on NVD →
Multiple Plugins <= Multiple Versions - Authenticated Remote Code Execution
high
Multiple plugins and/or themes for WordPress are vulnerable to Remote Code Execution in various versions. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.
- CVSS:
- 7.2
- Affected:
- up to 5.4.12
- Fixed in:
- 5.4.12
- Disclosed:
- Jun 15, 2026
CVE-2026-6382 on NVD →
Multiple elFinder Plugins <= (Various Versions) - Directory Traversal to Arbitrary File Deletion
medium
Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerability requires a site owner to explicitly make an instance of the file man...
- CVSS:
- 6.5
- Affected:
- up to 5.3.6
- Fixed in:
- 5.4.0
- Disclosed:
- Aug 12, 2025
CVE-2025-0818 on NVD →
Advanced File Manager <= 5.3.1 - Missing Authorization to Notice Dismisaal
medium
The Advanced File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on a function in versions up to, and including, 5.3.1. This makes it possible for unauthenticated attackers to dismiss admin notices.
- CVSS:
- 5.3
- Affected:
- up to 5.3.1
- Fixed in:
- 5.3.2
- Disclosed:
- May 7, 2025
CVE-2025-47688 on NVD →
Advanced File Manager – Ultimate WP File Manager And Document Library Solution [file-manager-advanced] <= 5.3.1 (unfixed)
unknown
[en] Missing Authorization vulnerability in Saad Iqbal Advanced File Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Advanced File Manager: from n/a through 5.3.1.
- Affected:
- up to 5.3.1
- Fix:
- No patched version reported
- Disclosed:
- May 7, 2025
CVE-2025-47688 on NVD →
Advanced File Manager – Ultimate WP File Manager And Document Library Solution [file-manager-advanced] < 5.3.0
unknown
[en] The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.2.14 due to insufficient input sanitization and output escaping. This makes it possible for authenti...
- Affected:
- up to 5.3.0
- Fixed in:
- 5.3.0
- Disclosed:
- Mar 7, 2025
CVE-2024-13805 on NVD →
Advanced File Manager <= 5.2.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload
medium
The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.2.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...
- CVSS:
- 6.4
- Affected:
- up to 5.2.14
- Fixed in:
- 5.3.0
- Disclosed:
- Mar 6, 2025
CVE-2024-13805 on NVD →
Advanced File Manager – Ultimate WP File Manager And Document Library Solution [file-manager-advanced] < 5.2.14
unknown
[en] The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fma_local_file_system' function in versions 5.2.12 to 5.2.13. This makes it possible for authenticated attackers, with Subscriber-level access and above and upload permissions granted...
- Affected:
- up to 5.2.14
- Fixed in:
- 5.2.14
- Disclosed:
- Jan 17, 2025
CVE-2024-13333 on NVD →
Advanced File Manager 5.2.12 - 5.2.13 - Authenticated (Subscriber+) Arbitrary File Upload
high
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fma_local_file_system' function in versions 5.2.12 to 5.2.13. This makes it possible for authenticated attackers, with Subscriber-level access and above and upload permissions granted by an...
- CVSS:
- 7.5
- Affected:
- 5.2.12 – 5.2.13
- Fixed in:
- 5.2.14
- Disclosed:
- Jan 16, 2025
CVE-2024-13333 on NVD →
Advanced File Manager – Ultimate WP File Manager And Document Library Solution [file-manager-advanced] < 5.2.11
unknown
[en] The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.10. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted per...
- Affected:
- up to 5.2.11
- Fixed in:
- 5.2.11
- Disclosed:
- Dec 3, 2024
CVE-2024-11391 on NVD →
Advanced File Manager <= 5.2.10 - Authenticated (Subscriber+) Arbitrary File Upload
high
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.10. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissi...
- CVSS:
- 7.5
- Affected:
- up to 5.2.10
- Fixed in:
- 5.2.11
- Disclosed:
- Dec 2, 2024
CVE-2024-11391 on NVD →
Advanced File Manager – Ultimate WP File Manager And Document Library Solution [file-manager-advanced] < 5.2.9
unknown
[en] The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 5.2.8 via the 'fma_locale' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary files on the se...
- Affected:
- up to 5.2.9
- Fixed in:
- 5.2.9
- Disclosed:
- Sep 26, 2024
CVE-2024-8704 on NVD →
Advanced File Manager – Ultimate WP File Manager And Document Library Solution [file-manager-advanced] < 5.2.9
unknown
[en] Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a lack of proper checks to ensure lower-privileged roles cannot upload .css and .js files to arbitrary directories. This makes it possible for authenticated attackers, with Subscriber-level access...
- Affected:
- up to 5.2.9
- Fixed in:
- 5.2.9
- Disclosed:
- Sep 26, 2024
CVE-2024-8725 on NVD →
Advanced File Manager – Ultimate WP File Manager And Document Library Solution [file-manager-advanced] < 5.2.9
unknown
[en] The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to uplo...
- Affected:
- up to 5.2.9
- Fixed in:
- 5.2.9
- Disclosed:
- Sep 26, 2024
CVE-2024-8126 on NVD →
Advanced File Manager <= 5.2.8 - Authenticated (Subscriber+) Arbitrary File Upload
high
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to upload a...
- CVSS:
- 7.5
- Affected:
- up to 5.2.8
- Fixed in:
- 5.2.9
- Disclosed:
- Sep 25, 2024
CVE-2024-8126 on NVD →
Advanced File Manager <= 5.2.8 - Authenticated (Administrator+) Local JavaScript File Inclusion via fma_locale
high
The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 5.2.8 via the 'fma_locale' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary files on the server,...
- CVSS:
- 7.2
- Affected:
- up to 5.2.8
- Fixed in:
- 5.2.9
- Disclosed:
- Sep 25, 2024
CVE-2024-8704 on NVD →
Advanced File Manager <= 5.2.8 - Authenticated (Subscriber+) Limited File Upload
medium
Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a lack of proper checks to ensure lower-privileged roles cannot upload .css and .js files to arbitrary directories. This makes it possible for authenticated attackers, with Subscriber-level access and...
- CVSS:
- 6.8
- Affected:
- up to 5.2.8
- Fixed in:
- 5.2.9
- Disclosed:
- Sep 25, 2024
CVE-2024-8725 on NVD →
Advanced File Manager – Ultimate WP File Manager And Document Library Solution [file-manager-advanced] < 5.2.5
unknown
[en] The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.4 via the 'fma_local_file_system' function. This makes it possible for unauthenticated attackers to extract sensitive data including backups or other sensitive information if the...
- Affected:
- up to 5.2.5
- Fixed in:
- 5.2.5
- Disclosed:
- Jun 29, 2024
CVE-2024-5598 on NVD →
Advanced File Manager <= 5.2.4 - Sensitive Information Exposure via Directory Listing
high
The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.4 via the 'fma_local_file_system' function. This makes it possible for unauthenticated attackers to extract sensitive data including backups or other sensitive information if the file...
- CVSS:
- 7.5
- Affected:
- up to 5.2.4
- Fixed in:
- 5.2.5
- Disclosed:
- Jun 28, 2024
CVE-2024-5598 on NVD →
Advanced File Manager – Ultimate WP File Manager And Document Library Solution [file-manager-advanced] < 5.1.1
unknown
[en] The Advanced File Manager WordPress plugin before 5.1.1 does not adequately authorize its usage on multisite installations, allowing site admin users to list and read arbitrary files and folders on the server.
- Affected:
- up to 5.1.1
- Fixed in:
- 5.1.1
- Disclosed:
- Sep 4, 2023
CVE-2023-3814 on NVD →
Advanced File Manager <= 5.1 - Authenticated (Administrator+) Arbitrary File and Folder Access
medium
The Advanced File Managerplugin for WordPress is vulnerable to improper access control in versions up to, and including, 5.1. This makes it possible for authenticated attackers, with administrator-level permissions and above, to access the filesystem on multisite installations. This only affects multi-site installation...
- CVSS:
- 6.6
- Affected:
- up to 5.1
- Fixed in:
- 5.1.1
- Disclosed:
- Aug 14, 2023
CVE-2023-3814 on NVD →
Advanced File Manager – Ultimate WP File Manager And Document Library Solution [file-manager-advanced] < 5.4.0
unknown
Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerability requires a site owner to explicitly make an instance of the file man...
- Affected:
- up to 5.4.0
- Fixed in:
- 5.4.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database