Advancedfilemanager develops a file-management application and associated WordPress shortcode plugin that operate in web-facing contexts, where the vendor's vulnerability profile reflects exposure endemic to user-upload and path-handling functionality. The disclosure pattern skews toward serious outcomes and demonstrates a moderate tendency toward public exploit availability, with recurring weaknesses spanning unrestricted file uploads, path traversal, cross-site scripting, authorization flaws, and insecure storage of sensitive data—classes characteristic of file-handling and plugin-based architectures. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Advancedfilemanager over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2068CRITICAL The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RC | Jun 27, 2023 | 9.8 | 71 | NO | YES |
CVE-2025-47688CRITICAL Missing Authorization vulnerability in Saad Iqbal Advanced File Manager file-manager-advanced allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff | May 7, 2025 | 9.8 | 26 | NO | NO |
CVE-2024-8126HIGH The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.8. This make | Sep 26, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-7061HIGH The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 2.5.3. This makes it possible for authentica | Jul 10, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-11391HIGH The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connector.php' file in all versions up | Dec 3, 2024 | 7.5 | 23 | NO | NO |
CVE-2024-13333HIGH The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fma_local_file_system' function in versions 5.2.1 | Jan 17, 2025 | 7.5 | 22 | NO | NO |
CVE-2024-8704HIGH The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 5.2.8 via the 'fma_locale' parameter. This mak | Sep 26, 2024 | 7.2 | 22 | NO | NO |
CVE-2024-5598HIGH The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.4 via the 'fma_local_file_system' function. | Jun 29, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-8725MEDIUM Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a lack of proper checks to ensure lower-privileged roles cann | Sep 26, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-13805MEDIUM The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in al | Mar 7, 2025 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Advancedfilemanager.
Media articles that mention a CVE ID that affects a product developed by Advancedfilemanager — matched by CVE ID, not by vendor name.