CVE-2024-5598
The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.4 via the 'fma_local_file_system' function. This makes it possible for unauthenticated attackers to extract sensitive data including backups or other sensitive information if the files have been moved to the built-in Trash folder.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.56%
- CWE
- CWE-922
- Published
- 2024-06-29
- Last modified
- 2026-04-09
Affected products
- modalweb Advanced File Manager
- saadiqbal Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution
Weakness type
Related vulnerabilities
- CVE-2026-44629 — Improper access control to the Synergis Softwire installation folder. This vulnerability affects...
- CVE-2026-20705 — Insecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform...
- CVE-2026-47362 — The Datadog Android application stores operationally sensitive content in plaintext SQLite...
- CVE-2026-46511 — HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack
- CVE-2025-32751 — Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information...
- CVE-2025-32746 — Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information...
- CVE-2026-7257 — ** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the...
- CVE-2026-40868 — kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token