Lucene search

K
cvelistWPScanCVELIST:CVE-2023-3814
HistorySep 04, 2023 - 11:27 a.m.

CVE-2023-3814 Advanced File Manager < 5.1.1 - Admin+ Arbitrary File/Folder Access

2023-09-0411:27:01
WPScan
www.cve.org
cve-2023-3814
file manager
wordpress
multisite
arbitrary access

5.4 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.3%

The Advanced File Manager WordPress plugin before 5.1.1 does not adequately authorize its usage on multisite installations, allowing site admin users to list and read arbitrary files and folders on the server.

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Advanced File Manager",
    "versions": [
      {
        "status": "affected",
        "versionType": "custom",
        "version": "0",
        "lessThan": "5.1.1"
      }
    ],
    "defaultStatus": "unaffected",
    "collectionURL": "https://wordpress.org/plugins"
  }
]

5.4 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.3%