CVE · High

CVE-2024-11391 — Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.2.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-11391 Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.2.11 Unrestricted Upload of File with Dangerous Type High 7.5 < 5.2.11 5.2.11 2024-12-02

CVE-2024-11391

The Advanced File Manager plugin for WordPress contains a file upload vulnerability caused by insufficient file type checking in the class_fma_connector.php file affecting versions 5.2.10 and earlier. Authenticated users with Subscriber role or higher permissions can exploit this flaw to upload malicious files to the server, potentially leading to remote code execution if an administrator has granted them the necessary permissions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.