CVE-2025-47688: WordPress Advanced File Manager plugin <= 5.3.1 - Broken Access Control to Notice Dismissal vulnerability
Missing Authorization vulnerability in Saad Iqbal Advanced File Manager file-manager-advanced allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced File Manager: from n/a through <= 5.3.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47688?
CVE-2025-47688 has been rated with a high severity due to missing authorization allowing unauthorized access to sensitive features.
How do I fix CVE-2025-47688?
To fix CVE-2025-47688, you should update the Saad Iqbal Advanced File Manager to version 5.3.2 or newer, where the issue is addressed.
What versions are affected by CVE-2025-47688?
CVE-2025-47688 affects versions of Saad Iqbal Advanced File Manager from n/a up to 5.3.1.
Can CVE-2025-47688 be exploited remotely?
Yes, CVE-2025-47688 can be exploited remotely due to misconfigured access controls that allow unauthorized file management access.
What are the potential impacts of CVE-2025-47688?
The impacts of CVE-2025-47688 include unauthorized file access and management, which can lead to data leakage or integrity breaches.