CVE Database /
CVE-2020-25213
CVE · Critical
CVE-2020-25213 — File Manager [wp-file-manager] < 6.9
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2020-25213
|
File Manager [wp-file-manager] < 6.9 |
Unrestricted Upload of File with Dangerous Type |
Critical
9.8
|
< 6.9
|
6.9 |
2020-09-01 |
—
|
CVE-2020-25213
The wp-file-manager plugin before version 6.9 contains an unauthenticated arbitrary file upload vulnerability that can lead to remote code execution. The vulnerable connector.minimal.php file is directly accessible and processes POST/GET parameters without authentication checks, allowing attackers to upload files including PHP scripts. This flaw was exploited in active attacks against WordPress sites running affected versions of the plugin.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings