PT-2026-73088 · WordPress · Advanced File Manager

·

CVE-2026-15009

·

Published

2026-08-16

·

Updated

2026-08-17

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution versions prior to 5.4.13
Description Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping. This allows unauthenticated attackers to inject arbitrary web scripts into pages. Execution happens when a user accesses the injected page. Successful exploitation requires the attacker to control a domain with an origin string that is a leading prefix of the target site's backend URL and requires an authenticated WordPress administrator to visit the attacker-controlled page while the File Manager admin screen is open. The issue is triggered via the soundFile parameter.
Recommendations Update Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution to version 5.4.13 or later. Avoid using the soundFile parameter until the plugin is updated.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15009

Affected Products

Advanced File Manager