CVE-2026-15009Disclosure

LOWCVSS 6.1 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'soundFile' parameter in all versions up to, and including, 5.4.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the attacker to control a domain whose origin string is a leading prefix of the target site's backend URL (e.g. https://example.co against https://example.com), and the victim must be an authenticated WordPress administrator who visits the attacker-controlled page while the File Manager admin screen is open.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-08-19)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-16: 1Mentions · 2026-08-19: 2Technical Details · 2026-08-16: 1Technical Details · 2026-08-19: 208-1608-19
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-08-161
General1
2026-08-192
Disclosure2
Full discourse3 posts
  • Ciberseguridad LATAM@CibersegLATAM
    Disclosure

    # CVE-2026-15009: falla XSS en plugin de WordPress explotable solo bajo condiciones de dominio específicas Una vulnerabilidad de severidad media en Advanced File Manager permite inyección de scripts, pero requiere que el atacante controle un dominio con prefijo coincidente con… https://t.co/3EO287DrKj

    Post summary

    The tweet announces a medium‑severity XSS flaw in the Advanced File Manager WordPress plugin that can only be exploited if the attacker controls a domain matching certain prefix conditions.

    10001665
    22.5K followersView on X
  • Ciberseguridad LATAM@CibersegLATAM
    Disclosure

    # CVE-2026-15009: falla XSS en plugin de WordPress explotable solo bajo condiciones de dominio específicas Una vulnerabilidad de severidad media en Advanced File Manager permite inyección de scripts, pero requiere que el atacante controle un dominio con prefijo coincidente con la

    Post summary

    The tweet announces a medium‑severity XSS flaw in the Advanced File Manager WordPress plugin that is only exploitable under specific domain conditions.

    1000055
    22.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-15009 Stored XSS in Advanced File Manager Plugin for WordPress via SoundFile Parameter https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-15009

    Post summary

    The text introduces a stored XSS vulnerability (CVE-2026-15009) in the Advanced File Manager WordPress plugin, affecting the SoundFile parameter, but provides limited technical detail and no evidence of active exploitation or mitigations.

    00000125
    4.1K followersView on X

Explore more