Stored Cross-Site Scripting Vulnerability in Advanced File Manager Plugin for WordPress
CVE-2026-15009

6.1MEDIUM

What is CVE-2026-15009?

The Advanced File Manager plugin for WordPress is susceptible to Stored Cross-Site Scripting through the 'soundFile' parameter due to inadequate input sanitization and output escaping. This vulnerability can be leveraged by unauthenticated attackers to inject malicious web scripts that execute on user access. Exploitation is contingent upon the attacker controlling a domain that matches a prefix of the target site’s backend URL, with the victim being an authenticated WordPress administrator who accesses the compromised page while the plugin's admin interface is open.

Affected Version(s)

Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution 0 <= 5.4.12

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

skyv3il
.