VendorsFilemanagerprofile_managerall versions
Vulnerabilities

Filemanagerpro File Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2020-25213
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to write PHP code into the wp-content/plugins/wp-file-manager/lib/files/ directory. This was exploited in the wild in August and September 2020.
Published 2020-09-09 · Analyzed
10.0KEV2 PoCEPSS 0.973
CVE-2018-25105
File Manager <= 3.0 - Unauthenticated Arbitrary File Upload/Download
Published 2024-10-16 · Analyzed
9.8EPSS 0.008
CVE-2023-6846
File Manager Pro <= 8.3.4 - Authenticated (Subscriber+) Arbitrary File Upload
Published 2024-02-05 · Modified
8.8EPSS 0.159
CVE-2024-1538
File Manager <= 7.2.4 - Cross-Site Request Forgery to Local JS File Inclusion
Published 2024-03-21 · Modified
8.8EPSS 0.107
CVE-2018-16966
There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.
Published 2019-04-15 · Modified
8.8EPSS 0.009
CVE-2024-8746
File Manager Pro <= 8.3.9 - Unauthenticated Backup File Download and Upload
Published 2024-10-16 · Analyzed
8.8EPSS 0.006
CVE-2024-8507
File Manager Pro <= 8.3.9 - Cross-Site Request Forgery to Arbitrary File Upload
Published 2024-10-16 · Analyzed
8.8EPSS 0.003
CVE-2024-0761
File Manager <= 7.2.1 - Sensitive Information Exposure via Backup Filenames
Published 2024-02-05 · Modified
8.1EPSS 0.010
CVE-2020-24312
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken.
Published 2020-08-26 · Modified
7.5EPSS 0.159
CVE-2024-8918
File Manager Pro <= 8.3.9 - Unauthenticated Limited JavaScript File Upload
Published 2024-10-16 · Analyzed
7.4EPSS 0.003
CVE-2024-2654
File Manager <= 7.2.5 - Authenticated (Administrator+) Directory Traversal
Published 2024-04-09 · Modified
6.8EPSS 0.009
CVE-2018-16967
There is an XSS vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.
Published 2019-04-15 · Modified
6.1EPSS 0.014
CVE-2018-16363
The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request because set_transient is used in file_folder_manager.php and there is an echo of lang in lib\wpfilemanager.php.
Published 2018-09-07 · Modified
5.4EPSS 0.014
CVE-2021-24177
WP File Manager < 7.1 - Reflected Cross-Site Scripting (XSS)
Published 2021-04-05 · Modified
5.4EPSS 0.009