CVE-2026-11565
Received Received - Intake

Advanced File Manager WordPress Plugin File Read and Write Vulnerabilities

Vulnerability report for CVE-2026-11565, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: WPScan

Description

The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing users with any role to which an administrator has granted file-manager access (as low as Subscriber) to read arbitrary files on the server β€” including sensitive configuration files β€” and to overwrite existing non-PHP files, which can be leveraged to compromise administrator accounts and the whole site.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-19
AI Q&A
2026-08-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
advanced_file_manager advanced_file_manager to 5.4.13 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Detection Guidance

Check if the Advanced File Manager plugin version is below 5.4.13. Use WordPress admin panel or run: wp plugin list | grep advanced_file_manager. Inspect server logs for unusual file read/write operations via AJAX calls like fma_load_fma_ui.

Mitigation Strategies

Update the Advanced File Manager plugin to version 5.4.13 or later immediately. Remove or disable the plugin if not essential. Review user roles with file-manager access and restrict unnecessary permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11565. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart