Advanced File Manager <= 5.1 - Authenticated (Administrator+) Arbitrary File and Folder Access
2023-08-14 00:00
Dmitrii IgnatyevStrategic Overview
StatusPatched in 5.1.1
Affected PluginAdvanced File Manager – Ultimate File Manager for WordPress And Document Library Solution
Affected Version
<= 5.1CVSS6.6Medium
CVE
CVE-2023-3814Vulnerability Overview
The Advanced File Managerplugin for WordPress is vulnerable to improper access control in versions up to, and including, 5.1. This makes it possible for authenticated attackers, with administrator-level permissions and above, to access the filesystem on multisite installations. This only affects multi-site installations.
Technical Analysis
REMEDIATION: Update to version 5.1.1, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C