Local File Inclusion Vulnerability in File Manager Advanced Shortcode WordPress Plugin by WordPress
CVE-2024-13914

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 May 2025

What is CVE-2024-13914?

The File Manager Advanced Shortcode plugin for WordPress is susceptible to Local File Inclusion in all versions up to and including 2.5.4 and 2.5.6 for the Advanced File Manager Pro Premium. Through the 'file_manager_advanced' shortcode, authenticated users with Administrator-level access can include and execute arbitrary JavaScript files on the server. This vulnerability can be exploited to bypass access controls, access sensitive information, or execute unauthorized code, particularly when trusted file types are allowed for upload and inclusion.

Affected Version(s)

File Manager Advanced Shortcode * <= 2.5.4

File Manager Advanced Shortcode * <= 2.5.6

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

TANG Cheuk Hei
.
CVE-2024-13914 : Local File Inclusion Vulnerability in File Manager Advanced Shortcode WordPress Plugin by WordPress