Arbitrary File Upload Vulnerability in Advanced File Manager for WordPress
CVE-2024-13333
7.5HIGH
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 17 January 2025
Summary
The Advanced File Manager plugin for WordPress is susceptible to an arbitrary file upload vulnerability caused by inadequate file type validation in its 'fma_local_file_system' function. This issue affects versions 5.2.12 and 5.2.13 and can be leveraged by authenticated users with Subscriber-level permissions or higher, provided they've been granted upload rights by an administrator. The vulnerability can be exploited if the 'Display .htaccess?' setting is enabled, allowing attackers to upload malicious files that may facilitate remote code execution on the affected site's server.
Affected Version(s)
Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin 5.2.12 <= 5.2.13
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
TANG Cheuk Hei