CVE-2024-5598 HIGH

CVE-2024-5598: Advanced File Manager <= 5.2.4 - Sensitive Information Exposure via Directory Listing

Vendor Saadiqbal
Product Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution
Weakness CWE-922
Published June 29, 2024
Last update April 8, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.4 via the 'fma_local_file_system' function. This makes it possible for unauthenticated attackers to extract sensitive data including backups or other sensitive information if the files have been moved to the built-in Trash folder.

Explanation of Vulnerability in Simple Terms

02Summary

Advanced File Manager for WordPress contains an information disclosure vulnerability affecting versions up to 5.2.4. An unauthenticated attacker can read sensitive data through the plugin without requiring user interaction. The vulnerability stems from improper access controls on file operations. Site administrators should update immediately to a version newer than 5.2.4.

What an attacker can do

03Attacker Capabilities

Read sensitive files and data from the site without authentication.

Potential impact on your site

04Site Impact

Confidential files, documents, or user data stored via the plugin may be exposed to the public internet.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

June 29, 2024 CVE published
April 8, 2026 Record updated

Related vulnerabilities

08Related CVE