Description
WordPress Plugin Advanced File Manager is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Advanced File Manager version 5.2.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.2.5 or latest
References
Related Vulnerabilities
WordPress Plugin Shopping Cart & eCommerce Store Arbitrary File Upload (3.0.8)
WordPress Plugin Infusionsoft Gravity Forms Add-on Arbitrary File Upload (1.5.10)
GeoServer Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2024-36401)
WordPress Plugin NextScripts:Social Networks Auto-Poster Cross-Site Scripting (4.3.20)
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-1000356)