CyberRota Analysis
AI-GeneratedThe Advanced File Manager plugin for WordPress prior to version 5.4.13 lacks proper capability checks in its AJAX file management actions, enabling users with minimal permissions, such as Subscribers, to read sensitive server files and overwrite non-PHP files. This vulnerability can lead to unauthorized access to sensitive configuration files and potential compromise of administrator accounts, posing a significant risk to the integrity of the entire site. WordPress site administrators and security teams should prioritize updating this plugin to mitigate the risk of exploitation.
Original NVD Description
The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing users with any role to which an administrator has granted file-manager access (as low as Subscriber) to read arbitrary files on the server — including sensitive configuration files — and to overwrite existing non-PHP files, which can be leveraged to compromise administrator accounts and the whole site.