WordPress Plugin Vulnerabilities
Advanced File Manager < 5.4.13 - Authenticated Arbitrary File Read and Write via fma_load_fma_ui
Description
The plugin does not perform capability checks in several of its file management AJAX actions, allowing users with any role to which an administrator has granted file-manager access (as low as Subscriber) to read arbitrary files on the server — including sensitive configuration files — and to overwrite existing non-PHP files, which can be leveraged to compromise administrator accounts and the whole site.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Christian Kold Jensen
Submitter
Christian Kold Jensen
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-17 (about 3 days ago)
Added
2026-08-17 (about 2 days ago)
Last Updated
2026-08-18 (about 1 day ago)