Vulnerabilities > Advancedfilemanager

DATE CVE VULNERABILITY TITLE RISK
2023-09-04 CVE-2023-3814 Incorrect Authorization vulnerability in Advancedfilemanager Advanced File Manager
The Advanced File Manager WordPress plugin before 5.1.1 does not adequately authorize its usage on multisite installations, allowing site admin users to list and read arbitrary files and folders on the server.
network
low complexity
advancedfilemanager CWE-863
4.9
2023-06-27 CVE-2023-2068 Unspecified vulnerability in Advancedfilemanager File Manager Advanced Shortcode 2.3.2
The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode.
network
low complexity
advancedfilemanager
critical
9.8