Local File Inclusion Vulnerability in File Manager Advanced Shortcode WordPress Plugin by WordPress
CVE-2024-13914
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 May 2025
What is CVE-2024-13914?
The File Manager Advanced Shortcode plugin for WordPress is susceptible to Local File Inclusion in all versions up to and including 2.5.4 and 2.5.6 for the Advanced File Manager Pro Premium. Through the 'file_manager_advanced' shortcode, authenticated users with Administrator-level access can include and execute arbitrary JavaScript files on the server. This vulnerability can be exploited to bypass access controls, access sensitive information, or execute unauthorized code, particularly when trusted file types are allowed for upload and inclusion.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
File Manager Advanced Shortcode * <= 2.5.4
File Manager Advanced Shortcode * <= 2.5.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved