CVE Vulnerabilities

CVE-2024-5598

Published: Jun 29, 2024 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.4 via the fma_local_file_system function. This makes it possible for unauthenticated attackers to extract sensitive data including backups or other sensitive information if the files have been moved to the built-in Trash folder.

Affected Software

NameVendorStart VersionEnd Version
Advanced_file_managerAdvancedfilemanager*5.2.5 (excluding)

References