Description


The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4. This makes it possible for attackers with contributor access or higher to read the contents of arbitrary files on the server, which can contain sensitive information.

Related CPE's


Could not find any relations

Weaknesses



CWE-538

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.8 · High

Information


Source identifier

[email protected]

Vulnerability status

Deferred

Published

2024-07-10T02:15:02.960Z

2 years ago

Last modified

2026-06-17T06:51:58.910Z

3 months ago