Description
The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing users with any role to which an administrator has granted file-manager access (as low as Subscriber) to read arbitrary files on the server — including sensitive configuration files — and to overwrite existing non-PHP files, which can be leveraged to compromise administrator accounts and the whole site.
Published: 2026-08-19
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Advanced File Manager plugin for WordPress allows a user who has been granted file-manager capability, even as a low‑privileged role such as Subscriber, to send AJAX requests that bypass capability checks. This flaw enables authenticated users to read any file on the server, including sensitive configuration files, and to overwrite existing non‑PHP files. The ability to modify configuration files or upload malicious content can lead to full site compromise and potentially provide attackers with an avenue to elevate privileges or gain administrative control.

Affected Systems

WordPress sites using the Advanced File Manager plugin prior to version 5.4.13. The vulnerability is present in all installations of the plugin regardless of the WordPress version, as it depends on the plugin’s AJAX action handlers. Any site that has enabled the file‑manager feature is susceptible if the plugin has not been upgraded.

Risk and Exploitability

The CVSS score of 8.5 classifies this flaw as high severity. The EPSS score of less than 1% indicates a low probability of exploitation observed so far, but the flaw remains exploitable because the attacker only requires a legitimate authenticated session with file‑manager access. It is not listed in the CISA KEV catalog. Attackers can exploit it by creating or using an account that has been granted file‑manager capability, then sending crafted AJAX requests to fma_load_fma_ui to read or overwrite arbitrary files. Once sensitive files are accessed or modified, the overall site and administrator accounts can be compromised.

Generated by OpenCVE AI on August 20, 2026 at 08:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Advanced File Manager plugin to version 5.4.13 or later.
  • If the plugin cannot be upgraded, disable or remove the file‑manager feature so that no users can trigger the vulnerable AJAX actions.
  • Restrict the file‑manager capability to trusted administrator accounts only and remove it from lower‑privileged roles.
  • Deploy a web application firewall rule that blocks attempts to access the fma_load_fma_ui endpoint from unauthenticated or low‑privileged sessions.

Generated by OpenCVE AI on August 20, 2026 at 08:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 20 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 19 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 19 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Advancedfilemanager
Advancedfilemanager advanced File Manager
Wordpress
Wordpress wordpress
Vendors & Products Advancedfilemanager
Advancedfilemanager advanced File Manager
Wordpress
Wordpress wordpress

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing users with any role to which an administrator has granted file-manager access (as low as Subscriber) to read arbitrary files on the server — including sensitive configuration files — and to overwrite existing non-PHP files, which can be leveraged to compromise administrator accounts and the whole site.
Title Advanced File Manager < 5.4.13 - Authenticated Arbitrary File Read and Write via fma_load_fma_ui
References

Subscriptions

Advancedfilemanager Advanced File Manager
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-19T12:52:52.335Z

Reserved: 2026-06-08T08:25:50.611Z

Link: CVE-2026-11565

cve-icon Vulnrichment

Updated: 2026-08-19T12:52:48.231Z

cve-icon NVD

Status : Deferred

Published: 2026-08-19T06:17:27.777

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-11565

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T08:30:04Z

Weaknesses