


Perceptive Security
SOC/SIEM Consultancy

The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pro WordPress plugin before 2.1.1, File M…
Published:
5 juli 2026 om 22:00:00
Alert date:
6 juli 2026 om 14:01:19
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
Multiple WordPress file manager plugins are vulnerable to OS Command Injection due to improper escaping of parameters passed to shell commands during image processing operations. Affected plugins include FileOrganizer (before 1.1.9), Advanced File Manager (before 5.4.12), File Manager Pro (before 2.1.1), and File Manager (before 8.0.4). Authenticated users can exploit this vulnerability to execute arbitrary OS commands on the server. Exploitation requires the ImageMagick convert CLI to be available on the server without the PHP imagick or GD extensions installed. This represents a significant risk as authenticated attackers could achieve full server compromise.
Technical details
Mitigation steps:
Affected products:
FileOrganizer WordPress plugin before 1.1.9
Advanced File Manager WordPress plugin before 5.4.12
File Manager Pro WordPress plugin before 2.1.1
File Manager WordPress plugin before 8.0.4
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-6382
https://wpscan.com/vulnerability/a27f70b7-a4cc-42fa-88c1-19adfe1593a8/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
