CVE · High

CVE-2024-5598 — Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.2.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-5598 Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.2.5 Insecure Storage of Sensitive Information High 7.5 < 5.2.5 5.2.5 2024-06-28

CVE-2024-5598

The Advanced File Manager plugin for WordPress contains a sensitive information exposure vulnerability in versions 5.2.4 and earlier through the 'fma_local_file_system' function that allows unauthenticated attackers to access confidential data such as backups and other sensitive files that have been relocated to the plugin's Trash folder. The vulnerability affects all installations running the vulnerable versions and could enable unauthorized exposure of stored sensitive materials. Version 5.2.5 and later address this security flaw.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.