← back to popular plugins
wordfence / plugin · file-manager-advanced
Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution
file-manager-advanced
total installs
100,000
total vulns
2
critical
0
high
0
medium
2
low
0
latest vuln
—
patched
2
unpatched
0
avg time to patch
—
vulnerabilities
(2)
Multiple elFinder Plugins <= (Various Versions) - Directory Traversal to Arbitrary File Deletion
medium
✓ patched
cve id
CVE-2025-0818 ↗
cvss score
6.5
cwe
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
published
Aug 12, 2025
Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerability requires a site owner to explicitly make an instance of the file manager available to users.
Advanced File Manager <= 5.3.1 - Missing Authorization to Notice Dismisaal
medium
✓ patched
The Advanced File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on a function in versions up to, and including, 5.3.1. This makes it possible for unauthenticated attackers to dismiss admin notices.