CVE Database /
CVE-2018-25105
CVE · Critical
CVE-2018-25105 — File Manager [wp-file-manager] < 3.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2018-25105
|
File Manager [wp-file-manager] < 3.1 |
Missing Authorization |
Critical
9.8
|
< 3.1
|
3.1 |
2018-09-17 |
—
|
CVE-2018-25105
The File Manager plugin for WordPress through version 3.0 lacks proper capability checks in the /inc/root.php file, allowing unauthenticated attackers to bypass authorization restrictions. This vulnerability enables unauthorized users to download any file from the affected server or upload malicious files that could lead to remote code execution.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings