Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-6382: Multiple WordPress Plugins Unauthenticated OS Command Injection
CVE-2026-6382 · published 2 months ago
Summary
Several popular WordPress plugins, including FileOrganizer, Advanced File Manager, File Manager Pro, and File Manager, contain a security flaw that allows attackers to execute system commands on the server. This could potentially lead to unauthorized access or data manipulation. To protect your website, update the affected plugins to the latest versions.
Original advisory text
The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pro WordPress plugin before 2.1.1, File Manager WordPress plugin before 8.0.4 ...
The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pro WordPress plugin before 2.1.1, File Manager WordPress plugin before 8.0.4 do not properly escape a parameter before passing it to a shell command when processing image operations, allowing authenticated users to perform OS Command Injection. This requires the server to have the ImageMagick convert CLI available without either the PHP imagick or GD extensions.
Severity
9.1
Critical
Exploitation
EPSS 1%
Timeline
Published6 Jul 2026
Updated22 Sep 2026
First seen6 Jul 2026
Sources
CVE-2026-6382 · NVD
Track software like this
Free during beta