What is CVE-2026-11565?
CVE-2026-11565 is a vulnerability in the Advanced File Manager WordPress plugin (versions before 5.4.13) where several file management AJAX actions lack proper capability checks. This allows users with any role granted file-manager access (as low as Subscriber) to read arbitrary files on the server. Administrators should immediately update the plugin to version 5.4.13 or later.
Azərbaycanca: CVE-2026-11565 Advanced File Manager WordPress plaginində (5.4.13-dən əvvəlki versiyalar) aşkar edilmiş bir zəiflikdir. Plagin, fayl idarəetməsi üzrə bəzi AJAX əməliyyatlarında yetki (capability) yoxlaması aparmır, bu da fayl menecerinə girişi olan istənilən rol sahibinə (məsələn, Subscriber) serverdəki ixtiyari faylları oxumağa imkan verir. Plagindən istifadə edən administrasiyalar dərhal 5.4.13 və ya daha yuxarı versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which minimally privileged user role can exploit CVE-2026-11565?
Any role granted file-manager access, as low as Subscriber, can exploit this vulnerability.
To which version of the Advanced File Manager plugin should you update to fix CVE-2026-11565?
You should update the plugin to version 5.4.13 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.