PLUGIN SECURITY
Is File Manager Advanced safe?
Use Advanced File Manager to manage WordPress files, create archives, and build document libraries—all directly from your WordPress dashboard!
What this plugin does
- Slug:
file-manager-advanced - Author: Saad Iqbal
- 100000+ active installs
- 96/100 rating (438 reviews on wordpress.org)
- 6159442 all-time downloads
- On WordPress.org since 2017-11-19
advance-file-managerdocument managementfile managerftpwp file manager
Maintenance status
- Latest known version: 5.4.12
- Last updated: 2026-08-13 11:02am GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.0+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
13 known CVEs on file for File Manager Advanced.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-15009 | Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.4.13 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 5.4.13 | 5.4.13 | 2026-08-15 | ⚠ update needed |
| CVE-2026-11565 | Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.4.13 | Missing Authorization | Unknown | < 5.4.13 | 5.4.13 | 2026-08-15 | ⚠ update needed |
| CVE-2026-6382 | Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.4.12 | Improper Control of Generation of Code ('Code Injection') | Unknown | < 5.4.12 | 5.4.12 | 2026-06-15 | ✓ fixed in latest |
| CVE-2025-47688 | Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.3.2 | Missing Authorization | Critical 9.8 | < 5.3.2 | 5.3.2 | 2025-05-07 | ✓ fixed in latest |
| CVE-2024-13805 | Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.3.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 5.3.0 | 5.3.0 | 2025-03-06 | ✓ fixed in latest |
| CVE-2024-13333 | Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.2.14 | Unrestricted Upload of File with Dangerous Type | High 7.5 | < 5.2.14 | 5.2.14 | 2025-01-16 | ✓ fixed in latest |
| CVE-2024-11391 | Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.2.11 | Unrestricted Upload of File with Dangerous Type | High 7.5 | < 5.2.11 | 5.2.11 | 2024-12-02 | ✓ fixed in latest |
| CVE-2024-8704 | Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.2.9 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 7.2 | < 5.2.9 | 5.2.9 | 2024-09-25 | ✓ fixed in latest |
+ 6 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-8725 | Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.2.9 | Unrestricted Upload of File with Dangerous Type | Medium 5.4 | < 5.2.9 | 5.2.9 | 2024-09-25 | ✓ fixed in latest |
| CVE-2024-8126 | Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.2.9 | Unrestricted Upload of File with Dangerous Type | High 8.8 | < 5.2.9 | 5.2.9 | 2024-09-25 | ✓ fixed in latest |
| CVE-2024-5598 | Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.2.5 | Insecure Storage of Sensitive Information | High 7.5 | < 5.2.5 | 5.2.5 | 2024-06-28 | ✓ fixed in latest |
| CVE-2023-3814 | Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.1.1 | Incorrect Authorization | Medium 4.9 | < 5.1.1 | 5.1.1 | 2023-08-14 | ✓ fixed in latest |
| — | Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.4.0 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Medium 6.5 | < 5.4.0 | 5.4.0 | 0000-00-00 | ✓ fixed in latest |
| CVE-2025-0818 | Multiple elFinder Plugins - Arbitrary File Deletion via Traversal | — | Unknown | < 5.4.0 | 5.4.0 | — | ✓ fixed in latest |
How to fix it
Keep File Manager Advanced updated — 5.4.12 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Download Manager — 100000+ active installs — 82/100 (1006) — max PHP 8.4
- Download Manager Addons for Elementor — 6000+ active installs — 44/100 (5)
- Document Library Lite — 4000+ active installs — 80/100 (11) — max PHP 8.4
- CatFolders Document Gallery & PDF Library — 3000+ active installs — 90/100 (14) — max PHP 8.4
- WP Document Revisions — 2000+ active installs — 74/100 (23)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.