CVE-2024-11010
The FileOrganizer – Manage WordPress and Website Files plugin through version 1.1.4 contains a local JavaScript file inclusion vulnerability in the 'default_lang' parameter that permits authenticated administrators to load and run arbitrary JavaScript files from the server. Attackers with administrator privileges could exploit this flaw to execute unauthorized JavaScript code, potentially circumventing security restrictions, accessing confidential information, or executing code when seemingly harmless files such as images have been uploaded. This issue was resolved in version 1.1.5.
Based on public CVE data (MITRE/NVD).