Filemanagerpro
Filemanagerpro File Manager: vulnerabilities and CVEs
Filemanagerpro File Manager has 14 published vulnerabilities, 0 of them in the last 12 months. 2 are rated critical and 1 are listed by CISA as actively exploited.
CVEs14
Last 12 months0
Critical2
Actively exploited1
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-25213 | Critical (9.8) | 97% | ⚠ Active exploitation | Sep 9, 2020 | The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8918 | Medium (5.4) | 0.34% | — | Oct 16, 2024 | The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 8.3.9. This is due to a lack of proper checks on allowed file types. This makes it possible… |
| CVE-2024-8746 | High (8.8) | 0.65% | — | Oct 16, 2024 | The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing file type validation via the 'mk_file_folder_manager_shortcode' ajax action in all versions up to,… |
| CVE-2024-8507 | High (8.8) | 0.25% | — | Oct 16, 2024 | The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.3.9. This is due to missing or incorrect nonce validation on the 'mk_file_folder_manager'… |
| CVE-2018-25105 | Critical (9.8) | 0.81% | — | Oct 16, 2024 | The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, and including, 3.0. This makes it possible for unauthenticated… |
| CVE-2024-2654 | Medium (6.8) | 0.91% | — | Apr 9, 2024 | The File Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.2.5 via the fm_download_backup function. This makes it possible for authenticated attackers, with… |
| CVE-2024-1538 | High (8.8) | 11% | — | Mar 21, 2024 | The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.4. This is due to missing or incorrect nonce validation on the wp_file_manager page that… |
| CVE-2024-0761 | High (7.5) | 1.0% | — | Feb 5, 2024 | The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.1 due to insufficient randomness in the backup filenames, which use a timestamp plus 4… |
| CVE-2023-6846 | High (8.8) | 16% | — | Feb 5, 2024 | The File Manager Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.3.4 via the mk_check_filemanager_php_syntax AJAX function. This makes it possible for… |
| CVE-2021-24177 | Medium (5.4) | 0.90% | — | Apr 5, 2021 | In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint /wp-admin/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent… |
| CVE-2020-25213 | Critical (9.8) | 97% | ⚠ Active exploitation | Sep 9, 2020 | The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php… |
| CVE-2020-24312 | High (7.5) | 16% | — | Aug 26, 2020 | mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site… |
| CVE-2018-16967 | Medium (6.1) | 1.4% | — | Apr 15, 2019 | There is an XSS vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter. |
| CVE-2018-16966 | High (8.8) | 0.92% | — | Apr 15, 2019 | There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter. |
| CVE-2018-16363 | Medium (5.4) | 1.4% | — | Sep 7, 2018 | The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request because set_transient is used in file_folder_manager.php and there is an echo… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.