CVE Database /
CVE-2024-13333
CVE · High
CVE-2024-13333 — Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.2.14
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-13333
|
Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.2.14 |
Unrestricted Upload of File with Dangerous Type |
High
7.5
|
< 5.2.14
|
5.2.14 |
2025-01-16 |
—
|
CVE-2024-13333
The Advanced File Manager plugin contains a file upload vulnerability in versions 5.2.12 to 5.2.13 affecting the 'fma_local_file_system' function, which fails to properly validate uploaded file types. Authenticated users with Subscriber-level permissions or higher who have been granted upload privileges can exploit this to upload arbitrary files to the server, potentially enabling remote code execution. The vulnerability only becomes exploitable when the "Display .htaccess?" option is enabled in the plugin settings.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings