High severity7.4NVD Advisory· Published Oct 16, 2024· Updated Jun 17, 2026
CVE-2024-8918
CVE-2024-8918
Description
The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 8.3.9. This is due to a lack of proper checks on allowed file types. This makes it possible for unauthenticated attackers, with permissions granted by an administrator, to upload .css and .js files, which could lead to Stored Cross-Site Scripting.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:filemanagerpro:file_manager:*:*:*:*:pro:wordpress:*:*Range: <8.3.10
- Range: <=8.3.9
- File Manager/File Manager Prov5Range: 0
Patches
Vulnerability mechanics
References
2- www.wordfence.com/threat-intel/vulnerabilities/id/01ef62c8-e862-422c-948d-6d376d021c82nvdThird Party Advisory
- filemanagerpro.ionvdProduct
News mentions
0No linked articles in our index yet.