CVE · High

CVE-2023-3664 — FileOrganizer – WordPress File Manager [fileorganizer] < 1.0.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-3664 FileOrganizer – WordPress File Manager [fileorganizer] < 1.0.4 Improper Access Control High 7.2 < 1.0.4 1.0.4 2023-09-03

CVE-2023-3664

The FileOrganizer plugin contains insufficient access control mechanisms that allow authenticated administrators to manipulate files across multi-site WordPress installations in versions 1.0.3 and earlier, despite such capabilities being restricted to super administrators only. This vulnerability enables users with standard admin privileges to gain unauthorized control over files that should remain protected at the network level. The flaw was addressed in version 1.0.4.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.