CVE-2023-7062 HIGH

CVE-2023-7062: Advanced File Manager Shortcodes <= 2.4 - Authenticated (Contributor+) Directory Traversal

Vendor Advanced File Manager
Product Advanced File Manager Shortcodes
Weakness CWE-538
Published July 10, 2024
Last update April 8, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4. This makes it possible for attackers with contributor access or higher to read the contents of arbitrary files on the server, which can contain sensitive information.

Explanation of Vulnerability in Simple Terms

02Summary

Advanced File Manager Shortcodes versions 2.4 and earlier contain a vulnerability allowing authenticated users with low privileges to read, modify, or delete files on the site. The vulnerability requires a valid user account but no special permissions. An attacker can exploit this to access sensitive data, alter site content, or disrupt availability.

What an attacker can do

03Attacker Capabilities

Read, modify, or delete files on the site with the privileges of the web server.

Potential impact on your site

04Site Impact

Any registered user can potentially access or alter sensitive files, including configuration and database backups.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege user account on the site; no user interaction required.

Key dates

06Disclosure timeline

July 10, 2024 CVE published
April 8, 2026 Record updated

Related vulnerabilities

08Related CVE