CVE-2024-11391: Advancedfilemanager Advanced File Manager
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.10. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected products
- Advancedfilemanager Advanced File Manager: before 5.2.11 (fixed in 5.2.11)
Published 2024-12-03. Last modified 2026-06-17.