Sceawere

Vulnerability Detail

CVE-2026-15009UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Advanced File Manager Stored XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
5h ago
Vendor
saadiqbal
Product
Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'soundFile' parameter in all versions up to, and including, 5.4.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the attacker to control a domain whose origin string is a leading prefix of the target site's backend URL (e.g. https://example.co against https://example.com), and the victim must be an authenticated WordPress administrator who visits the attacker-controlled page while the File Manager admin screen is open.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-08-16T05:16:46.753Z",
  "pubdate": "2026-08-16T05:16:46.753Z",
  "executiveSummary": "The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS).\nThe vulnerability exists in all versions up to, and including, 5.4.12.\nIt arises due to insufficient input sanitization and output escaping via the 'soundFile' parameter.\nUnauthenticated attackers can leverage this flaw to inject arbitrary web scripts into pages.\nInjected scripts execute whenever a user accesses an injected page.\nExploitation requires the attacker to control a domain whose origin string is a leading prefix of the target site's backend URL, such as https://example.co against https://example.com.\nAdditionally, the victim must be an authenticated WordPress administrator who visits the attacker-controlled page while the File Manager admin screen is open.\nThe impact includes potential execution of arbitrary JavaScript within the administrative context, leading to administrative session compromise or unauthorized administrative actions.",
  "technicalDetails": "The vulnerability is classified as Stored Cross-Site Scripting (XSS) stemming from improper handling of user-supplied input.\nThe vulnerable component is the parameter 'soundFile' within the Advanced File Manager plugin.\nAffected versions include all iterations up to, and including, 5.4.12.\nThe root cause of the vulnerability is the lack of rigorous input sanitization and context-aware output escaping on the 'soundFile' parameter before it is reflected or stored.\nAuthentication and privilege requirements for the initial injection do not restrict unauthenticated attackers from submitting the payload, though successful exploitation relies on specific environmental and interaction conditions.\nThe attack flow proceeds as follows: First, the unauthenticated attacker crafts a malicious payload targeting the 'soundFile' parameter within the plugin context. Second, the attacker must control a domain whose origin string acts as a leading prefix of the target site's backend URL (e.g., controlling https://example.co when the target backend URL is https://example.com). Third, a targeted victim, specifically an authenticated WordPress administrator, must visit the attacker-controlled page while concurrently having the File Manager administrative screen open.\nWhen these conditions align, the browser executes the injected arbitrary web scripts within the context of the administrator's session.\nThe payload behavior involves running arbitrary JavaScript in the administrative interface, which can lead to post-exploitation impacts such as administrative privilege escalation, creation of rogue administrator accounts, or unauthorized modification of site files and database contents via the file manager capabilities."
}
CVE-2026-15009: Advanced File Manager Stored XSS (MEDIUM Severity, CVSS: 6.1) - Sceawere