Extension WordPress
Vulnérabilités Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution
Cette page rassemble les failles publiées pour Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution
10 fiches
Multiple elFinder Plugins <= (Various Versions) – Directory Traversal to Arbitrary File Deletion
Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerability requires a site owner to…
*-5.3.6
5.4.0
12/08/2025
Advanced File Manager <= 5.3.1 – Missing Authorization to Notice Dismisaal
The Advanced File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on a function in versions up to, and including, 5.3.1. This makes it possible for unauthenticated attackers to…
*-5.3.1
5.3.2
07/05/2025
Advanced File Manager <= 5.2.14 – Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload
The Advanced File Manager , Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.2.14 due to insufficient input…
*-5.2.14
5.3.0
06/03/2025
Advanced File Manager 5.2.12 – 5.2.13 – Authenticated (Subscriber+) Arbitrary File Upload
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fma_local_file_system' function in versions 5.2.12 to 5.2.13. This makes it possible for authenticated attackers, with Subscriber-level access…
5.2.12-5.2.13
5.2.14
16/01/2025
Advanced File Manager <= 5.2.10 – Authenticated (Subscriber+) Arbitrary File Upload
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.10. This makes it possible for authenticated attackers,…
*-5.2.10
5.2.11
02/12/2024
Advanced File Manager <= 5.2.8 – Authenticated (Subscriber+) Limited File Upload
Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a lack of proper checks to ensure lower-privileged roles cannot upload .css and .js files to arbitrary directories. This…
*-5.2.8
5.2.9
25/09/2024
Advanced File Manager <= 5.2.8 – Authenticated (Subscriber+) Arbitrary File Upload
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, and…
*-5.2.8
5.2.9
25/09/2024
Advanced File Manager <= 5.2.8 – Authenticated (Administrator+) Local JavaScript File Inclusion via fma_locale
The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 5.2.8 via the 'fma_locale' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above,…
*-5.2.8
5.2.9
25/09/2024
Advanced File Manager <= 5.2.4 – Sensitive Information Exposure via Directory Listing
The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.4 via the 'fma_local_file_system' function. This makes it possible for unauthenticated attackers to extract sensitive data including backups…
*-5.2.4
5.2.5
28/06/2024
Advanced File Manager <= 5.1 – Authenticated (Administrator+) Arbitrary File and Folder Access
The Advanced File Managerplugin for WordPress is vulnerable to improper access control in versions up to, and including, 5.1. This makes it possible for authenticated attackers, with administrator-level permissions and above, to access the filesystem on multisite installations.…
*-5.1
5.1.1
14/08/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.