Impact
The Advanced File Manager plugin for WordPress allows a user who has been granted file-manager capability, even as a low‑privileged role such as Subscriber, to send AJAX requests that bypass capability checks. This flaw enables authenticated users to read any file on the server, including sensitive configuration files, and to overwrite existing non‑PHP files. The ability to modify configuration files or upload malicious content can lead to full site compromise and potentially provide attackers with an avenue to elevate privileges or gain administrative control.
Affected Systems
WordPress sites using the Advanced File Manager plugin prior to version 5.4.13. The vulnerability is present in all installations of the plugin regardless of the WordPress version, as it depends on the plugin’s AJAX action handlers. Any site that has enabled the file‑manager feature is susceptible if the plugin has not been upgraded.
Risk and Exploitability
The CVSS score of 8.5 classifies this flaw as high severity. The EPSS score of less than 1% indicates a low probability of exploitation observed so far, but the flaw remains exploitable because the attacker only requires a legitimate authenticated session with file‑manager access. It is not listed in the CISA KEV catalog. Attackers can exploit it by creating or using an account that has been granted file‑manager capability, then sending crafted AJAX requests to fma_load_fma_ui to read or overwrite arbitrary files. Once sensitive files are accessed or modified, the overall site and administrator accounts can be compromised.
OpenCVE Enrichment