๐Ÿ” CVE Alert

CVE-2026-11565

UNKNOWN 0.0

Advanced File Manager < 5.4.13 - Authenticated Arbitrary File Read and Write via fma_load_fma_ui

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing users with any role to which an administrator has granted file-manager access (as low as Subscriber) to read arbitrary files on the server โ€” including sensitive configuration files โ€” and to overwrite existing non-PHP files, which can be leveraged to compromise administrator accounts and the whole site.

Vendor unknown
Product advanced file manager
Published Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for unknown advanced file manager

Be the first to know when new unknown vulnerabilities affecting unknown advanced file manager are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Advanced File Manager
0 < 5.4.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/5e03858d-db0b-4b65-99cc-eb01ad4195e9/

Credits

Christian Kold Jensen WPScan