CVE · High

CVE-2024-13333 — Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.2.14

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-13333 Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.2.14 Unrestricted Upload of File with Dangerous Type High 7.5 < 5.2.14 5.2.14 2025-01-16

CVE-2024-13333

The Advanced File Manager plugin contains a file upload vulnerability in versions 5.2.12 to 5.2.13 affecting the 'fma_local_file_system' function, which fails to properly validate uploaded file types. Authenticated users with Subscriber-level permissions or higher who have been granted upload privileges can exploit this to upload arbitrary files to the server, potentially enabling remote code execution. The vulnerability only becomes exploitable when the "Display .htaccess?" option is enabled in the plugin settings.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.