CVE Database /
CVE-2024-11391
CVE · High
CVE-2024-11391 — Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.2.11
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-11391
|
Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.2.11 |
Unrestricted Upload of File with Dangerous Type |
High
7.5
|
< 5.2.11
|
5.2.11 |
2024-12-02 |
—
|
CVE-2024-11391
The Advanced File Manager plugin for WordPress contains a file upload vulnerability caused by insufficient file type checking in the class_fma_connector.php file affecting versions 5.2.10 and earlier. Authenticated users with Subscriber role or higher permissions can exploit this flaw to upload malicious files to the server, potentially leading to remote code execution if an administrator has granted them the necessary permissions.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings