CVE · High

CVE-2024-0761 — File Manager [wp-file-manager] < 7.2.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-0761 File Manager [wp-file-manager] < 7.2.2 Use of Insufficiently Random Values High 7.5 < 7.2.2 7.2.2 2024-01-22

CVE-2024-0761

The File Manager plugin for WordPress through version 7.2.1 allows unauthenticated attackers to access sensitive data and site backups because backup filenames are generated with insufficient randomness, relying only on a timestamp combined with four random digits. When the .htaccess file fails to restrict access to the backup directory, attackers can predict and retrieve these backup files. This vulnerability exposes sensitive information that should remain protected from unauthorized access.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.