Vulnerabilities > Advancedfilemanager > Advanced File Manager > 1.2

DATE CVE VULNERABILITY TITLE RISK
2025-05-07 CVE-2025-47688 Missing Authorization vulnerability in Advancedfilemanager Advanced File Manager
Missing Authorization vulnerability in Saad Iqbal Advanced File Manager allows Exploiting Incorrectly Configured Access Control Security Levels.
network
low complexity
advancedfilemanager CWE-862
critical
9.8
2025-03-07 CVE-2024-13805 Cross-site Scripting vulnerability in Advancedfilemanager Advanced File Manager
The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.2.14 due to insufficient input sanitization and output escaping.
network
low complexity
advancedfilemanager CWE-79
5.4
2024-09-26 CVE-2024-8126 Unrestricted Upload of File with Dangerous Type vulnerability in Advancedfilemanager Advanced File Manager
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.8.
network
low complexity
advancedfilemanager CWE-434
8.8
2024-09-26 CVE-2024-8704 Path Traversal vulnerability in Advancedfilemanager Advanced File Manager
The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 5.2.8 via the 'fma_locale' parameter.
network
low complexity
advancedfilemanager CWE-22
7.2
2024-09-26 CVE-2024-8725 Unrestricted Upload of File with Dangerous Type vulnerability in Advancedfilemanager Advanced File Manager
Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions.
network
low complexity
advancedfilemanager CWE-434
5.4
2023-09-04 CVE-2023-3814 Incorrect Authorization vulnerability in Advancedfilemanager Advanced File Manager
The Advanced File Manager WordPress plugin before 5.1.1 does not adequately authorize its usage on multisite installations, allowing site admin users to list and read arbitrary files and folders on the server.
network
low complexity
advancedfilemanager CWE-863
4.9