CVE · Critical

CVE-2020-25213 — File Manager [wp-file-manager] < 6.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-25213 File Manager [wp-file-manager] < 6.9 Unrestricted Upload of File with Dangerous Type Critical 9.8 < 6.9 6.9 2020-09-01

CVE-2020-25213

The wp-file-manager plugin before version 6.9 contains an unauthenticated arbitrary file upload vulnerability that can lead to remote code execution. The vulnerable connector.minimal.php file is directly accessible and processes POST/GET parameters without authentication checks, allowing attackers to upload files including PHP scripts. This flaw was exploited in active attacks against WordPress sites running affected versions of the plugin.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.