plugin

File Manager Advanced Shortcode Vulnerabilities

8 known security issues reported for the File Manager Advanced Shortcode WordPress plugin. Most recent disclosed May 15, 2025.

1 critical 3 high

Running File Manager Advanced Shortcode on your site? Check whether your installed version is affected.

Scan your site free

File Manager Advanced Shortcode [file-manager-advanced-shortcode] <= 2.5.4 (unfixed)

unknown

[en] The File Manager Advanced Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.4 (file-manager-advanced-shortcode) and 2.5.6 (advanced-file-manager-pro-premium), via the 'file_manager_advanced' shortcode. This makes it possible for authenticated attackers,...

Affected:
up to 2.5.4
Fix:
No patched version reported
Disclosed:
May 15, 2025

CVE-2024-13914 on NVD →

File Manager Advanced Shortcode <= Multiple Versions - Authenticated (Administrator+) Local JavaScript File Inclusion via Shortcode

high

The File Manager Advanced Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.4 (file-manager-advanced-shortcode) and 2.5.6 (advanced-file-manager-pro-premium), via the 'file_manager_advanced' shortcode. This makes it possible for authenticated attackers, with...

CVSS:
7.2
Affected:
up to 2.5.4
Fixed in:
2.6.0
Disclosed:
May 14, 2025

CVE-2024-13914 on NVD →

File Manager Advanced Shortcode [file-manager-advanced-shortcode] < 2.5.4

unknown

[en] The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 2.5.3. This makes it possible for authenticated attackers with contributor access or above to upload arbitrary files on the affected site's server which may make remote code execu...

Affected:
up to 2.5.4
Fixed in:
2.5.4
Disclosed:
Jul 10, 2024

CVE-2023-7061 on NVD →

File Manager Advanced Shortcode [file-manager-advanced-shortcode] < 2.4.1

unknown

[en] The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4. This makes it possible for attackers with contributor access or higher to read the contents of arbitrary files on the server, which can contain sensitive information.

Affected:
up to 2.4.1
Fixed in:
2.4.1
Disclosed:
Jul 10, 2024

CVE-2023-7062 on NVD →

Advanced File Manager Shortcode <= 2.5.3 - Authenticated (Contributor+) Arbitrary File Upload

high

The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 2.5.3. This makes it possible for authenticated attackers with contributor access or above to upload arbitrary files on the affected site's server which may make remote code execution...

CVSS:
8.8
Affected:
up to 2.5.3
Fixed in:
2.5.4
Disclosed:
Jul 8, 2024

CVE-2023-7061 on NVD →

Advanced File Manager Shortcodes <= 2.4 - Authenticated (Contributor+) Directory Traversal

high

The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4. This makes it possible for attackers with contributor access or higher to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS:
8.8
Affected:
up to 2.4
Fixed in:
2.4.1
Disclosed:
Jul 8, 2024

CVE-2023-7062 on NVD →

File Manager Advanced Shortcode [file-manager-advanced-shortcode] < 2.4

unknown

[en] The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users.

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
Jun 27, 2023

CVE-2023-2068 on NVD →

File Manager Advanced Shortcode WordPress <= 2.3.2 - Unauthenticated Arbitrary File Upload to Remote Code Execution via Shortcode

critical

The File Manager Advanced Shortcode WordPress plugin for WordPress is vulnerable to remote code execution in versions up to, and including, 2.3.2. This is due to the plugin allowing users to upload PHP files when the shortcode has been added to a page/post. This makes it possible for unauthenticated users to potentiall...

CVSS:
9.8
Affected:
up to 2.3.2
Fixed in:
2.4
Disclosed:
May 31, 2023

CVE-2023-2068 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database