CVE-2023-3814

MEDIUM

WordPress Advanced File Manager <5.1.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Advanced File Manager WordPress plugin before 5.1.1 does not adequately authorize its usage on multisite installations, allowing site admin users to list and read arbitrary files and folders on the server.

References (1)

Core 1
Core References
Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/ca954ec6-6ebd-4d72-a323-570474e2e339

Scores

CVSS v3 4.9
EPSS 0.0050
EPSS Percentile 39.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
advancedfilemanager/advanced_file_manager < 5.1.1
Published Sep 04, 2023
Tracked Since Feb 18, 2026