Vulnerabilities > Advancedfilemanager > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-09-26 CVE-2024-8725 Unrestricted Upload of File with Dangerous Type vulnerability in Advancedfilemanager Advanced File Manager
Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions.
network
low complexity
advancedfilemanager CWE-434
5.4
2023-09-04 CVE-2023-3814 Incorrect Authorization vulnerability in Advancedfilemanager Advanced File Manager
The Advanced File Manager WordPress plugin before 5.1.1 does not adequately authorize its usage on multisite installations, allowing site admin users to list and read arbitrary files and folders on the server.
network
low complexity
advancedfilemanager CWE-863
4.9