WordPress Plugins and Themes Vulnerable to Limited File Upload Attack
CVE-2024-8725
5.4MEDIUM
What is CVE-2024-8725?
A vulnerability exists in several WordPress plugins and themes that allows for limited file upload due to inadequate validation mechanisms. This flaw permits authenticated attackers with Subscriber-level access and higher to upload .css and .js files to any location within the WordPress root directory. The exploit requires the Advanced File Manager Shortcodes plugin to be installed. As a result, this could potentially facilitate Stored Cross-Site Scripting attacks, causing further security risks for the affected websites.
Affected Version(s)
Advanced File Manager * <= 5.2.8