SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-11565

HIGH · CVSS 8.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Advanced File Manager plugin for WordPress prior to version 5.4.13 lacks proper capability checks in its AJAX file management actions, enabling users with minimal permissions, such as Subscribers, to read sensitive server files and overwrite non-PHP files. This vulnerability can lead to unauthorized access to sensitive configuration files and potential compromise of administrator accounts, posing a significant risk to the integrity of the entire site. WordPress site administrators and security teams should prioritize updating this plugin to mitigate the risk of exploitation.

CVE
CVE-2026-11565
Severity
HIGH
CVSS
8.5
EPSS
0.24%
WordPress

Original NVD Description

The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing users with any role to which an administrator has granted file-manager access (as low as Subscriber) to read arbitrary files on the server — including sensitive configuration files — and to overwrite existing non-PHP files, which can be leveraged to compromise administrator accounts and the whole site.