PT-2026-73088 · WordPress · Advanced File Manager
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution versions prior to 5.4.13
Description
Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping. This allows unauthenticated attackers to inject arbitrary web scripts into pages. Execution happens when a user accesses the injected page. Successful exploitation requires the attacker to control a domain with an origin string that is a leading prefix of the target site's backend URL and requires an authenticated WordPress administrator to visit the attacker-controlled page while the File Manager admin screen is open. The issue is triggered via the
soundFile parameter.Recommendations
Update Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution to version 5.4.13 or later.
Avoid using the
soundFile parameter until the plugin is updated.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Advanced File Manager