CVE-2026-11565
Advanced File Manager < 5.4.13 - Authenticated Arbitrary File Read and Write via fma_load_fma_ui
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing users with any role to which an administrator has granted file-manager access (as low as Subscriber) to read arbitrary files on the server โ including sensitive configuration files โ and to overwrite existing non-PHP files, which can be leveraged to compromise administrator accounts and the whole site.
| Vendor | unknown |
| Product | advanced file manager |
| Published | Aug 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown advanced file manager
Be the first to know when new unknown vulnerabilities affecting unknown advanced file manager are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Advanced File Manager
0 < 5.4.13
References
Credits
Christian Kold Jensen WPScan