Extension WordPress
Vulnérabilités File Manager Advanced Shortcode
Cette page rassemble les failles publiées pour File Manager Advanced Shortcode, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de File Manager Advanced Shortcode
4 fiches
File Manager Advanced Shortcode <= Multiple Versions – Authenticated (Administrator+) Local JavaScript File Inclusion via Shortcode
The File Manager Advanced Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.4 (file-manager-advanced-shortcode) and 2.5.6 (advanced-file-manager-pro-premium), via the 'file_manager_advanced' shortcode. This makes it possible for authenticated attackers, with…
*-2.5.4
2.6.0
14/05/2025
Advanced File Manager Shortcode <= 2.5.3 – Authenticated (Contributor+) Arbitrary File Upload
The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 2.5.3. This makes it possible for authenticated attackers with contributor access or above to upload arbitrary files…
*-2.5.3
2.5.4
08/07/2024
Advanced File Manager Shortcodes <= 2.4 – Authenticated (Contributor+) Directory Traversal
The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4. This makes it possible for attackers with contributor access or higher to read the contents of arbitrary…
*-2.4
2.4.1
08/07/2024
File Manager Advanced Shortcode WordPress <= 2.3.2 – Unauthenticated Arbitrary File Upload to Remote Code Execution via Shortcode
The File Manager Advanced Shortcode WordPress plugin for WordPress is vulnerable to remote code execution in versions up to, and including, 2.3.2. This is due to the plugin allowing users to upload PHP files when the shortcode has…
*-2.3.2
2.4
31/05/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.