CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-11565

highCVSS 8.5covered by 1 sourcefirst seen 2026-08-19
The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing users with any role to which an administrator has granted file-manager access (as low as Subscriber) to read arbitrary files on the server — including sensitive configuration files — and to overwrite existing non-PHP files, which can be leveraged to compromise administrator accounts and the whole site.

⚡ Watch CVE-2026-11565

Get an email if CVE-2026-11565 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-11565

CVE.org record

Embed the live status

CVE-2026-11565 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-11565 status](https://www.csirts.com/badge/CVE-2026-11565)](https://www.csirts.com/cve/CVE-2026-11565)