WordPress Plugins and Themes Vulnerable to Limited File Upload Attack
CVE-2024-8725
What is CVE-2024-8725?
A vulnerability exists in several WordPress plugins and themes that allows for limited file upload due to inadequate validation mechanisms. This flaw permits authenticated attackers with Subscriber-level access and higher to upload .css and .js files to any location within the WordPress root directory. The exploit requires the Advanced File Manager Shortcodes plugin to be installed. As a result, this could potentially facilitate Stored Cross-Site Scripting attacks, causing further security risks for the affected websites.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Advanced File Manager * <= 5.2.8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved