Extension WordPress

Vulnérabilités Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution

Cette page rassemble les failles publiées pour Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution, leurs plages de versions affectées et les correctifs signalés dans la base locale.

10Vulnérabilités
0Critiques
10Avec correctif
7,5CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution

10 fiches

CVE-2025-0818 Moyenne · 6,5
Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution

Multiple elFinder Plugins <= (Various Versions) – Directory Traversal to Arbitrary File Deletion

Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerability requires a site owner to…

Versions affectées

*-5.3.6

Correctif

5.4.0

Publication

12/08/2025

CVE-2025-47688 Informationnelle
Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution

Advanced File Manager <= 5.3.1 – Missing Authorization to Notice Dismisaal

The Advanced File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on a function in versions up to, and including, 5.3.1. This makes it possible for unauthenticated attackers to…

Versions affectées

*-5.3.1

Correctif

5.3.2

Publication

07/05/2025

CVE-2024-13805 Moyenne · 6,4
Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution

Advanced File Manager <= 5.2.14 – Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload

The Advanced File Manager , Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.2.14 due to insufficient input…

Versions affectées

*-5.2.14

Correctif

5.3.0

Publication

06/03/2025

CVE-2024-13333 Élevée · 7,5
Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution

Advanced File Manager 5.2.12 – 5.2.13 – Authenticated (Subscriber+) Arbitrary File Upload

The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fma_local_file_system' function in versions 5.2.12 to 5.2.13. This makes it possible for authenticated attackers, with Subscriber-level access…

Versions affectées

5.2.12-5.2.13

Correctif

5.2.14

Publication

16/01/2025

CVE-2024-11391 Élevée · 7,5
Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution

Advanced File Manager <= 5.2.10 – Authenticated (Subscriber+) Arbitrary File Upload

The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.10. This makes it possible for authenticated attackers,…

Versions affectées

*-5.2.10

Correctif

5.2.11

Publication

02/12/2024

CVE-2024-8725 Moyenne · 6,8
Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution

Advanced File Manager <= 5.2.8 – Authenticated (Subscriber+) Limited File Upload

Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a lack of proper checks to ensure lower-privileged roles cannot upload .css and .js files to arbitrary directories. This…

Versions affectées

*-5.2.8

Correctif

5.2.9

Publication

25/09/2024

CVE-2024-8126 Élevée · 7,5
Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution

Advanced File Manager <= 5.2.8 – Authenticated (Subscriber+) Arbitrary File Upload

The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, and…

Versions affectées

*-5.2.8

Correctif

5.2.9

Publication

25/09/2024

CVE-2024-8704 Élevée · 7,2
Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution

Advanced File Manager <= 5.2.8 – Authenticated (Administrator+) Local JavaScript File Inclusion via fma_locale

The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 5.2.8 via the 'fma_locale' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above,…

Versions affectées

*-5.2.8

Correctif

5.2.9

Publication

25/09/2024

CVE-2024-5598 Élevée · 7,5
Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution

Advanced File Manager <= 5.2.4 – Sensitive Information Exposure via Directory Listing

The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.4 via the 'fma_local_file_system' function. This makes it possible for unauthenticated attackers to extract sensitive data including backups…

Versions affectées

*-5.2.4

Correctif

5.2.5

Publication

28/06/2024

CVE-2023-3814 Moyenne · 6,6
Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution

Advanced File Manager <= 5.1 – Authenticated (Administrator+) Arbitrary File and Folder Access

The Advanced File Managerplugin for WordPress is vulnerable to improper access control in versions up to, and including, 5.1. This makes it possible for authenticated attackers, with administrator-level permissions and above, to access the filesystem on multisite installations.…

Versions affectées

*-5.1

Correctif

5.1.1

Publication

14/08/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités