{"error":0,"message":null,"data":{"name":"File Manager","plugin":"wp-file-manager","link":"https:\/\/wordpress.org\/plugins\/wp-file-manager\/","latest":"1776775980","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"5f1416255276b40adc38a9c4853f5ca1e948ea2afcbfdc6e4a10918ea726fa27","name":"File Manager [wp-file-manager] < 7.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24177","name":"CVE-2021-24177","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24177","description":"[en] In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint \/wp-admin\/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then reflected back on the web application response.","date":"2021-04-05"},{"id":"90ee3c648c0b26a7dda9b5dc0c98be5bf7b111fa","name":"WP File Manager <= 7.0 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-file-manager\/wp-file-manager-70-reflected-cross-site-scripting","description":"In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint \/wp-admin\/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then reflected back on the web application response.","date":"2021-02-26"},{"id":"1cf3d256-cf4b-4d1f-9ed8-e2cc6392d8d8","name":"WP File Manager &lt; 7.1 - Reflected Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/1cf3d256-cf4b-4d1f-9ed8-e2cc6392d8d8","description":"During a quick security auditing of the plugin, in the default configuration a Reflected XSS can occur on the endpoint \/wp-admin\/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then reflected back on the web application response.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"11482958c04fe1f1b22c6afdcd4e979c58e8b17e55730f2fe012fcf3257a32d7","name":"File Manager [wp-file-manager] < 6.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-25213","name":"CVE-2020-25213","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-25213","description":"[en] The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to write PHP code into the wp-content\/plugins\/wp-file-manager\/lib\/files\/ directory. This was exploited in the wild in August and September 2020.","date":"2020-09-09"},{"id":"c570006de12072d56a0f7a74db893f858523905e","name":"WordPress File Manager plugin <= 6.8 - Unauthenticated Arbitrary File Upload leading to RCE vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-file-manager\/vulnerability\/wordpress-file-manager-plugin-6-8-unauthenticated-arbitrary-file-upload-leading-to-rce-vulnerability","description":"Unauthenticated Arbitrary File Upload leading to RCE vulnerability found by w4fz5uck5 in WordPress File Manager plugin (versions <= 6.8).","date":"2020-09-01"},{"id":"1e00f590f54bb66c27eeedf8765e7ded4acf4d8d","name":"File Manager <= 6.8 - Arbitrary File Upload\/Remote Code Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-file-manager\/file-manager-68-arbitrary-file-uploadremote-code-execution","description":"The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to write PHP code into the wp-content\/plugins\/wp-file-manager\/lib\/files\/ directory. This was exploited in the wild in August and September 2020.","date":"2020-09-01"},{"id":"e528ae38-72f0-49ff-9878-922eff59ace9","name":"File Manager 6.0-6.9 - Unauthenticated Arbitrary File Upload leading to RCE","link":"https:\/\/wpscan.com\/vulnerability\/e528ae38-72f0-49ff-9878-922eff59ace9","description":"Seravo noticed multiple cases where WordPress sites were breached using 0-day in wp-file-manager (confirmed with v6.8, which was the latest version available in wordpress.org).\r\n\r\nFile lib\/php\/connector.minimal.php can be by default opened directly, and this  file loads lib\/php\/elFinderConnector.class.php which reads POST\/GET variables, and then allows executing some internal features, like uploading files. PHP is allowed, thus this leads to unauthenticated arbitrary file upload and remote code execution.\r\n\r\nIt seems that this vulnerability was originally discovered and published publicly on Twitter on August 26th (see references), and was later seen being exploited in the wild by Seravo.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."}],"ssvc":{"exploitation":"active","automatable":"yes","technical_impact":"total","kev":true,"kev_date":"2021-11-03"}}},{"uuid":"92238c10c033411318b1fc78da1dd124f2df3e6e4e96b0dce10fcc4c246ebfa0","name":"File Manager [wp-file-manager] < 3.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-16967","name":"CVE-2018-16967","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-16967","description":"[en] There is an XSS vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.","date":"2019-04-15"},{"id":"431e7a72c0b0d37a3d2d0cdd5638881ae9cdfba8","name":"File Manager <= 3.0 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-file-manager\/file-manager-30-stored-cross-site-scripting","description":"There is an XSS vulnerability in the File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.","date":"2018-09-17"},{"id":"50bd65b2-b546-47c0-8cdc-2e650319744c","name":"File Manager &lt; 3.1 - CSRF to Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/50bd65b2-b546-47c0-8cdc-2e650319744c","description":"The plugin is lacking CSRF as well as sanitisation checks, allowing attackers to perform CSRF attacks against logged in administrators and set an XSS payload in the public_path setting.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"7cf63552462c6728c8910ce6512874b596bbc3231f59488c4f9f4a1daba61b1c","name":"File Manager [wp-file-manager] < 3.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-16966","name":"CVE-2018-16966","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-16966","description":"[en] There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.","date":"2019-04-15"},{"id":"d8d1ca053bba3766485001d152f1a7a1f8a9a120","name":"File Manager <= 3.0 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-file-manager\/file-manager-30-cross-site-request-forgery","description":"There is a CSRF vulnerability in the File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.","date":"2018-09-17"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"d0586f6eb4f960927c91c827aee66af5011bfb3e53dba3eb493c679fbde4be4d","name":"File Manager [wp-file-manager] < 3.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-16363","name":"CVE-2018-16363","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-16363","description":"[en] The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin\/admin.php?page=wp_file_manager request because set_transient is used in file_folder_manager.php and there is an echo of lang in lib\\wpfilemanager.php.","date":"2018-09-07"},{"id":"6a0f94e03fb5c3fd45a99f45437f1025ebd189c7","name":"WordPress File Manager plugin <= 2.9 - Authenticated Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/file-manager\/vulnerability\/wordpress-file-manager-plugin-2-9-authenticated-cross-site-scripting-xss-vulnerability","description":"Authenticated Cross-Site Scripting (XSS) vulnerability found by ly55521 in WordPress File Manager plugin (versions <= 2.9).","date":"2018-09-09"},{"id":"9266cd116bdcd9fd8134ee9579483f6475b429c7","name":"File Manager <= 2.9 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-file-manager\/file-manager-29-reflected-cross-site-scripting","description":"The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin\/admin.php?page=wp_file_manager request because set_transient is used in file_folder_manager.php and there is an echo of lang in lib\\wpfilemanager.php.","date":"2018-09-06"},{"id":"65e4849b-6517-400d-884f-65234f58ab0c","name":"File Manager &lt; 3.0 - Authenticated Reflected Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/65e4849b-6517-400d-884f-65234f58ab0c","description":"Lack of sanitisation in the lang parameter in the admin dashboard could allow attacker to perform reflected XSS attacks against logged in administrators","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"9d67add6dc20b045eae31aa559a91523000fc60548c8200a05d932285f4698fe","name":"File Manager [wp-file-manager] < 6.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-24312","name":"CVE-2020-24312","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-24312","description":"[en] mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken.","date":"2020-08-26"},{"id":"547c30391a0bc0d0e3c253b656e739f476d89236","name":"WordPress File Manager plugin <= 6.4 - Backup File Directory Listing vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-file-manager\/vulnerability\/wordpress-file-manager-plugin-6-4-backup-file-directory-listing-vulnerability","description":"Backup File Directory Listing vulnerability found by zerodetail & ratherbland in WordPress File Manager plugin (versions <= 6.4).","date":"2020-08-26"},{"id":"f3da6294276cda3efce4da98fdfdaddcf1be4cfd","name":"WP File Manager <= 6.4 - Unauthenticated Resource Access to Site Backups","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-file-manager\/wp-file-manager-64-unauthenticated-resource-access-to-site-backups","description":"mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken.","date":"2020-08-13"},{"id":"49533dc2-17cb-459c-af28-69a7b9b9512f","name":"File Manager &lt; 6.5 - Backup File Directory Listing","link":"https:\/\/wpscan.com\/vulnerability\/49533dc2-17cb-459c-af28-69a7b9b9512f","description":"The File Manager WordPress plugin could expose backup files if the web server had Directory Listing enabled.\r\n\r\nThe File Manager WordPress plugin, version 6.4 and lower, failed to restrict external access to the fm_backups directory with a .htaccess file. This resulted in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, which the plugin had taken.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-552","name":"Files or Directories Accessible to External Parties","description":"The product makes files or directories accessible to unauthorized actors, even though they should not be."}]}},{"uuid":"d15d62ba0c644795e5babec775a2ba060722b7be5b4bcf4c75d75678e51c890e","name":"File Manager [wp-file-manager] < 4.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"a0d4145b135ede5ebba85863200b1fde333d4153","name":"File Manager <= 4.8 - Missing Authorization on AJAX Actions","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-file-manager\/file-manager-48-missing-authorization-on-ajax-actions","description":"The File Manager plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various functions hooked via AJAX actions in versions up to, and including, 4.8. This makes it possible for authenticated attackers with subscriber-level permissions and above to delete back-ups and view sensitive information about back-ups.","date":"2019-08-07"}],"impact":[]},{"uuid":"a405f2a3129a824136b1bf7b2cb61eef0d818d5d8b0c32cf7f347b31fed27f0f","name":"File Manager [wp-file-manager] < 3.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"70d9f29b5770613904cf87693bbfa7607cf59e9a","name":"File Manager <= 3.0 - Unauthenticated Arbitrary File Upload\/Download","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-file-manager\/file-manager-30-unauthenticated-arbitrary-file-uploaddownload","description":"The  File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the \/inc\/root.php file in versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to download arbitrary files from the server and upload arbitrary files that can be used for remote code execution.","date":"2018-09-17"},{"id":"CVE-2018-25105","name":"CVE-2018-25105","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-25105","description":"[en] The  File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the \/inc\/root.php file in versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to download arbitrary files from the server and upload arbitrary files that can be used for remote code execution.","date":"2024-10-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"b9ebbaa9911090e4b4f786f828e5a6c6e97925c85baed32b3dc10aba6ee549fc","name":"File Manager [wp-file-manager] < 5.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6f1a4455-051c-4f10-b0cb-e0d29e401c9e","name":"File Manager &lt; 5.2 - Multiple Vulnerabilities","link":"https:\/\/wpscan.com\/vulnerability\/6f1a4455-051c-4f10-b0cb-e0d29e401c9e","description":"Multiple vulnerabilities exist due to not checking the authentication of the user properly in the wp_ajax_* action calls. This results in SQL injection, backup download, backup deletion and backup restoration in the backup feature of the plugin. Authentication is required, but this can be of any user role.\r\n\r\nEdit (WPScanTeam):\r\nOriginal advisory reported fixed in 4.9, however the 4.9 was missing CSRF checks, which have been added in 5.1","date":null}],"impact":[]},{"uuid":"4777a4caf0f518a1e5dd6e1f031a8053416173c12130ca5cc9cab3134ec26ea9","name":"File Manager [wp-file-manager] < 7.2.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.2.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8593d3708e42582396d74379c1be5bd7beeedfdf","name":"File Manager <= 7.2.1 - Sensitive Information Exposure via Backup Filenames","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-file-manager\/file-manager-721-sensitive-information-exposure-via-backup-filenames","description":"The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.1 due to insufficient randomness in the backup filenames, which use a timestamp plus 4 random digits. This makes it possible for unauthenticated attackers, to extract sensitive data including site backups in configurations where the .htaccess file in the directory does not block access.","date":"2024-01-22"},{"id":"CVE-2024-0761","name":"CVE-2024-0761","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-0761","description":"[en] The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.1 due to insufficient randomness in the backup filenames, which use a timestamp plus 4 random digits. This makes it possible for unauthenticated attackers, to extract sensitive data including site backups in configurations where the .htaccess file in the directory does not block access.","date":"2024-02-05"},{"id":"9786db035245b078efa8956965d791455cb1aa77","name":"WordPress  File Manager Plugin  <= 7.2.1 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-file-manager\/vulnerability\/wordpress-file-manager-plugin-7-2-1-sensitive-information-exposure-via-backup-filenames-vulnerability","description":"Update the WordPress File Manager plugin to the latest available version (at least 7.2.2).\nYuki Haruma discovered and reported this Sensitive Data Exposure vulnerability in WordPress File Manager Plugin.  This vulnerability has been fixed in version 7.2.2.\nHave additional information or questions about this entry? Get in touch.","date":"2024-01-23"},{"id":"e1b4077a-2b56-4fd9-9a19-d758dacb08a4","name":"File Manager &lt; 7.2.2 - Sensitive Information Exposure via Backup Filenames","link":"https:\/\/wpscan.com\/vulnerability\/e1b4077a-2b56-4fd9-9a19-d758dacb08a4","description":"The plugin is vulnerable to Sensitive Information Exposure due to insufficient randomness in the backup filenames, which use a timestamp plus 4 random digits. This makes it possible for unauthenticated attackers, to extract sensitive data including site backups in configurations where the .htaccess file in the directory does not block access.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-330","name":"Use of Insufficiently Random Values","description":"The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"3070d12718b1e530a3045cec0ffabba9123e71691fe5bd1b84d2d1874da8f744","name":"File Manager [wp-file-manager] < 7.2.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.2.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6825","name":"CVE-2023-6825","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6825","description":"[en] The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the  mk_file_folder_manager_action_callback_shortcode function. This makes it possible for attackers to read the contents of arbitrary files on the server, which can contain sensitive information and to upload files into directories other than the intended directory for file uploads. The free version requires Administrator access for this vulnerability to be exploitable. The Pro version allows a file manager to be embedded via a shortcode and also allows admins to grant file handling privileges to other user levels, which could lead to this vulnerability being exploited by lower-level users.","date":"2024-03-13"},{"id":"f4446d9da1604f0b31d61d644b54e9650a9ed6f8","name":"File Manager And File Manager Pro (Multiple Versions) - Directory Traversal","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/file-manager-and-file-manager-pro-multiple-versions-directory-traversal","description":"The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the  mk_file_folder_manager_action_callback_shortcode function. This makes it possible for attackers to read the contents of arbitrary files on the server, which can contain sensitive information and to upload files into directories other than the intended directory for file uploads. The free version requires Administrator access for this vulnerability to be exploitable. The Pro version allows a file manager to be embedded via a shortcode and also allows admins to grant file handling privileges to other user levels, which could lead to this vulnerability being exploited by lower-level users.","date":"2024-03-04"},{"id":"388170dc8add45c923b14f224cf33a1940d2b616","name":"WordPress  File Manager Plugin    <= 7.2.1 is vulnerable to Path Traversal","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-file-manager\/vulnerability\/wordpress-file-manager-plugin-7-2-1-directory-traversal-vulnerability","description":"Update the WordPress File Manager plugin to the latest available version (at least 7.2.2).\nTobias Wei\u00dfhaar (kun_19) discovered and reported this Path Traversal vulnerability in WordPress File Manager Plugin.  This vulnerability has been fixed in version 7.2.2.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"e04c3f89-55c7-4d8c-9a11-a16cc64079e9","name":"File Manager And File Manager Pro (Multiple Versions) - Directory Traversal","link":"https:\/\/wpscan.com\/vulnerability\/e04c3f89-55c7-4d8c-9a11-a16cc64079e9","description":"The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the  mk_file_folder_manager_action_callback_shortcode function. This makes it possible for attackers to read the contents of arbitrary files on the server, which can contain sensitive information and to upload files into directories other than the intended directory for file uploads. The free version requires Administrator access for this vulnerability to be exploitable. The Pro version allows a file manager to be embedded via a shortcode and also allows admins to grant file handling privileges to other user levels, which could lead to this vulnerability being exploited by lower-level users.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"h","i":"h","a":"h","score":"9.9","severity":"c","exploitable":"3.1","impact":"6.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:H\/A:H","score":"9.9","severity":"critical","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"high","i":"high","a":"high","exploitable":"3.1","impact":"6.0"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."},{"cwe":"CWE-23","name":"Relative Path Traversal","description":"The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as \"..\" that can resolve to a location that is outside of that directory."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"ab556b23a27a358a7fdbcb3cd09516060d72807e212260816264a92a13c9a728","name":"File Manager [wp-file-manager] < 7.2.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.2.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1538","name":"CVE-2024-1538","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1538","description":"[en] The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.4. This is due to missing or incorrect nonce validation on the wp_file_manager page that includes files through the 'lang' parameter. This makes it possible for unauthenticated attackers to include local JavaScript files that can be leveraged to achieve RCE via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This issue was partially patched in version 7.2.4, and fully patched in 7.2.5.","date":"2024-03-21"},{"id":"4896f646ad506695b35e121bded8ef88ca9bc565","name":"File Manager <= 7.2.4 - Cross-Site Request Forgery to Local JS File Inclusion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-file-manager\/file-manager-724-cross-site-request-forgery-to-local-js-file-inclusion","description":"The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.4. This is due to missing or incorrect nonce validation on the wp_file_manager page that includes files through the 'lang' parameter. This makes it possible for unauthenticated attackers to include local JavaScript files that can be leveraged to achieve RCE via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This issue was partially patched in version 7.2.4, and fully patched in 7.2.5.","date":"2024-03-20"},{"id":"f3a6ea363299cd466fb2e3038dce3b16ad4b5dd9","name":"WordPress  File Manager Plugin    <= 7.2.4 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-file-manager\/vulnerability\/wordpress-file-manager-plugin-7-2-4-cross-site-request-forgery-to-local-js-file-inclusion-vulnerability","description":"Update the WordPress File Manager plugin to the latest available version (at least 7.2.5).\n0xBishop discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress File Manager Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 7.2.5.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"fd0ed716-1e6b-4fcc-a5b4-cf03d07857e6","name":"File Manager &lt; 7.2.5 - Cross-Site Request Forgery to Local JS File Inclusion","link":"https:\/\/wpscan.com\/vulnerability\/fd0ed716-1e6b-4fcc-a5b4-cf03d07857e6","description":"The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonce validation on the wp_file_manager page that includes files through the &#039;lang&#039; parameter. This makes it possible for unauthenticated attackers to include local JavaScript files that can be leveraged to achieve RCE via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This issue was partially patched in version 7.2.4, and fully patched in 7.2.5.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"02925a5b5c3faaf30a0df8b3f14da23769dd053207187c2c06a5fb4ee331a44a","name":"File Manager [wp-file-manager] < 7.2.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.2.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2654","name":"CVE-2024-2654","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2654","description":"[en] The File Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.2.5 via the fm_download_backup function. This makes it possible for authenticated attackers, with administrator access and above, to read the contents of arbitrary zip files on the server, which can contain sensitive information.","date":"2024-04-09"},{"id":"c8921a10839191f2c4bf6a48e6b1bd085ec1e712","name":"File Manager <= 7.2.5 - Authenticated (Administrator+) Directory Traversal","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-file-manager\/file-manager-725-authenticated-administrator-directory-traversal","description":"The File Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.2.5 via the fm_download_backup function. This makes it possible for authenticated attackers, with administrator access and above, to read the contents of arbitrary zip files on the server, which can contain sensitive information.","date":"2024-04-03"},{"id":"2500fdc008c62b42c500a5e42a8fd39f431c034c","name":"WordPress  File Manager Plugin    <= 7.2.5 is vulnerable to Path Traversal","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-file-manager\/vulnerability\/wordpress-file-manager-plugin-7-2-5-authenticated-administrator-directory-traversal-vulnerability","description":"Update the WordPress File Manager plugin to the latest available version (at least 7.2.6).\nDarkT discovered and reported this Path Traversal vulnerability in WordPress File Manager Plugin.  This vulnerability has been fixed in version 7.2.6.\nHave additional information or questions about this entry? Get in touch.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"h","ui":"n","s":"c","c":"h","i":"n","a":"n","score":"6.8","severity":"m","exploitable":"2.3","impact":"4.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:H\/I:N\/A:N","score":"6.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"none","s":"changed","c":"high","i":"none","a":"none","exploitable":"2.3","impact":"4.0"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."},{"cwe":"CWE-35","name":"Path Traversal: '...\/...\/\/'","description":"The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '...\/...\/\/' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"289bfd16eebfbf58c6638de155f8d1cc0bcfcea2136ea4434a2084e86f831274","name":"File Manager [wp-file-manager] < 7.2.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.2.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-37254","name":"CVE-2024-37254","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-37254","description":"[en] Missing Authorization vulnerability in mndpsingh287 File Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects File Manager: from n\/a through 7.2.7.","date":"2024-11-01"},{"id":"247cc809808de0d21866c3c996e0d92a1bd9a344","name":"WordPress File Manager Plugin <= 7.2.7 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-file-manager\/vulnerability\/wordpress-wp-file-manager-plugin-7-2-7-broken-access-control-vulnerability","description":"<p>WordPress File Manager Plugin <= 7.2.7 is vulnerable to Broken Access Control<\/p><p>Software: File Manager<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wp-file-manager\/#developers<\/p><p>Affected Version <= 7.2.7<\/p><p>Fixed in version 7.2.8 <\/p>","date":"2024-06-27"},{"id":"9485a7e13fac6d4fe2424d0de3642f25a9c1ffb6","name":"File Manager <= 7.2.7 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-file-manager\/file-manager-727-missing-authorization","description":"The File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mk_file_manager_backup_callback function in versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to trigger backups","date":"2024-06-27"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"ab586db14bf1ba6d520040372dc5f152dd461861bbf8f1f9fb00217b6991f3dc","name":"File Manager [wp-file-manager] < 8.0.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.0.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-6382","name":"CVE-2026-6382","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-6382","description":"[en] The FileOrganizer  WordPress plugin before 1.1.9, Advanced File Manager  WordPress plugin before 5.4.12, File Manager Pro  WordPress plugin before 2.1.1, File Manager WordPress plugin before 8.0.4 do not properly escape a parameter before passing it to a shell command when processing image operations, allowing authenticated users to perform OS Command Injection. This requires the server to have the ImageMagick convert CLI available without either the PHP imagick or GD extensions.","date":"2026-07-06"},{"id":"727a5116fd93c2e435a1ad57af7bd90743ab316b","name":"Multiple Plugins <= Multiple Versions - Authenticated Remote Code Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/multiple-plugins-multiple-versions-authenticated-remote-code-execution","description":"Multiple plugins and\/or themes for WordPress are vulnerable to Remote Code Execution in various versions. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.","date":"2026-06-15"}],"impact":{"cwe":[{"cwe":"CWE-94","name":"Improper Control of Generation of Code ('Code Injection')","description":"The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}}]},"updated":"1783403065"}