← back to popular plugins
wordfence / plugin · file-manager-advanced

Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution

file-manager-advanced
total installs
100,000
total vulns
2
critical
0
high
0
medium
2
low
0
latest vuln
patched
2
unpatched
0
avg time to patch
vulnerabilities (2)
Multiple elFinder Plugins <= (Various Versions) - Directory Traversal to Arbitrary File Deletion
medium ✓ patched
cvss score 6.5
cwe CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
published Aug 12, 2025
Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerability requires a site owner to explicitly make an instance of the file manager available to users.
Advanced File Manager <= 5.3.1 - Missing Authorization to Notice Dismisaal
medium ✓ patched
cvss score 5.3
cwe CWE-862: Missing Authorization
published May 7, 2025
The Advanced File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on a function in versions up to, and including, 5.3.1. This makes it possible for unauthenticated attackers to dismiss admin notices.