The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing users with any role to which an administrator has granted file-manager access (as low as Subscriber) to read arbitrary files on the server — including sensitive configuration files — and to overwrite existing non-PHP files, which can be leveraged to compromise administrator accounts and the whole site.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The Advanced File Manager WordPress plugin before version 5.4.13 contains a critical authorization flaw that allows any user with file-manager access—including those with minimal privileges like Subscribers—to bypass capability checks in AJAX actions. This vulnerability enables arbitrary file reading and non-PHP file overwriting on the server, exposing sensitive configuration files that often contain database credentials and API keys. Organizations relying on this plugin face risk of complete site compromise, as attackers can leverage overwritten files to escalate privileges, create backdoors, and hijack administrator accounts. Any WordPress installation using this plugin before 5.4.13 with multi-user access should be considered immediately vulnerable.
While this CVE lacks explicit MITRE ATT&CK mappings, Casky's security skill framework would detect the attack patterns through techniques such as Exploitation of Vulnerability (T1190) and Privilege Escalation (T1134) by identifying suspicious AJAX requests that bypass authorization checks, unusual file access patterns targeting configuration files like wp-config.php, and file modification activity on non-executable assets. A practitioner using Casky would observe findings indicating unauthorized capability execution, anomalous file read operations crossing privilege boundaries, and write attempts to sensitive locations—patterns that Claude's extended reasoning capabilities correlate with post-exploitation activities aimed at persistence and lateral movement within the WordPress environment.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-11565. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation