The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.10. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible.
History

Thu, 05 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Advancedfilemanager
Advancedfilemanager advanced File Manager
CPEs cpe:2.3:a:advancedfilemanager:advanced_file_manager:*:*:*:*:*:wordpress:*:*
Vendors & Products Advancedfilemanager
Advancedfilemanager advanced File Manager

Tue, 03 Dec 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Modalweb
Modalweb advanced File Manager
CPEs cpe:2.3:a:modalweb:advanced_file_manager:*:*:*:*:*:*:*:*
Vendors & Products Modalweb
Modalweb advanced File Manager
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 03 Dec 2024 14:45:00 +0000

Type Values Removed Values Added
Description The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.10. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Title Advanced File Manager <= 5.2.10 - Authenticated (Subscriber+) Arbitrary File Upload
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-12-03T14:34:29.866Z

Updated: 2024-12-03T15:56:04.491Z

Reserved: 2024-11-18T22:42:04.474Z

Link: CVE-2024-11391

cve-icon Vulnrichment

Updated: 2024-12-03T15:55:59.354Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-03T15:15:09.973

Modified: 2025-06-05T15:49:38.117

Link: CVE-2024-11391

cve-icon Redhat

No data.