CVE · Medium

CVE-2024-8725 — Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.2.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-8725 Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.2.9 Unrestricted Upload of File with Dangerous Type Medium 5.4 < 5.2.9 5.2.9 2024-09-25

CVE-2024-8725

Authenticated users with elevated privileges can upload malicious CSS and JavaScript files to arbitrary directories on a WordPress site, provided they have access to the Advanced File Manager Shortcodes plugin. This is due to insufficient file validation controls that allow uploads by lower-privileged roles, including Subscribers and above, when granted permissions by an administrator. The vulnerability enables potential Stored Cross-Site Scripting attacks through these uploaded files.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.