Advanced File Manager <= 5.1 - Authenticated (Administrator+) Arbitrary File and Folder Access

2023-08-14 00:00
Dmitrii Ignatyev

Vulnerability Overview

The Advanced File Managerplugin for WordPress is vulnerable to improper access control in versions up to, and including, 5.1. This makes it possible for authenticated attackers, with administrator-level permissions and above, to access the filesystem on multisite installations. This only affects multi-site installations.

Technical Analysis

REMEDIATION: Update to version 5.1.1, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C