File Manager Advanced Shortcode

File Manager Advanced Shortcode has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; all 4 are fixed as of September 2026. Their average CVSS score is 8.7, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 3 high. 2024 was the busiest year with 2 disclosures.

The most common weakness is Code Injection, behind 1 of the records (25%). Other recurring categories include Insertion Of Sensitive Information Into Externally-Accessible File Or Directory, Path Traversal.

Every one of the 4 issues recorded for File Manager Advanced Shortcode has a vendor fix available, so running the current release closes all known holes.

3 independent researchers contributed these findings, most of them (2) reported by Colin Xu.

Strategic Overview

Avg CVSSHigh
8.7/ 10
Patch Coverage100%
Open

0

Fixed

4

Get automatic notifications for all File Manager Advanced Shortcode vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2023-2068

File Manager Advanced Shortcode WordPress <= 2.3.2 - Unauthenticated Arbitrary File Upload to Remote Code Execution via Shortcode

Read the full analysis

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C