Stored Cross-Site Scripting Vulnerability in Advanced File Manager Plugin for WordPress
CVE-2026-15009
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 August 2026
What is CVE-2026-15009?
The Advanced File Manager plugin for WordPress is susceptible to Stored Cross-Site Scripting through the 'soundFile' parameter due to inadequate input sanitization and output escaping. This vulnerability can be leveraged by unauthenticated attackers to inject malicious web scripts that execute on user access. Exploitation is contingent upon the attacker controlling a domain that matches a prefix of the target site’s backend URL, with the victim being an authenticated WordPress administrator who accesses the compromised page while the plugin's admin interface is open.
Affected Version(s)
Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution 0 <= 5.4.12