VYPR

Advanced File Manager

by Advancedfilemanager

CVEs (7)

  • CVE-2024-5598HigJun 29, 2024
    risk 0.42cvss 7.5epss 0.01

    The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.4 via the 'fma_local_file_system' function. This makes it possible for unauthenticated attackers to extract sensitive data including backups…

  • CVE-2025-47688MedMay 7, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Saad Iqbal Advanced File Manager file-manager-advanced allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced File Manager: from n/a through <= 5.3.1.

  • CVE-2024-4004May 15, 2025
    risk 0.00cvss epss 0.00

    The Advanced Cron Manager WordPress plugin before 2.5.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in…

  • CVE-2024-13333Jan 17, 2025
    risk 0.00cvss epss 0.01

    The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fma_local_file_system' function in versions 5.2.12 to 5.2.13. This makes it possible for authenticated attackers, with Subscriber-level access and…

  • CVE-2024-11391Dec 3, 2024
    risk 0.00cvss epss 0.01

    The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.10. This makes it possible for authenticated attackers, with…

  • CVE-2024-8126Sep 26, 2024
    risk 0.00cvss epss 0.01

    The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted…

  • CVE-2024-8704Sep 26, 2024
    risk 0.00cvss epss 0.01

    The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 5.2.8 via the 'fma_locale' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include…