VYPR

Advanced File Manager

Sign in to watch

by Advancedfilemanager

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2024-5598Hig0.497.50.01Jun 29, 2024The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.4 via the 'fma_local_file_system' function. This makes it possible for unauthenticated attackers to extract sensitive data including backups or other sensitive information if the files have been moved to the built-in Trash folder.
CVE-2025-47688Med0.345.30.00May 7, 2025Missing Authorization vulnerability in Saad Iqbal Advanced File Manager file-manager-advanced allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced File Manager: from n/a through <= 5.3.1.