CVE-2024-1538
The File Manager plugin for WordPress versions prior to 7.2.5 contains a cross-site request forgery vulnerability affecting the wp_file_manager page, where nonce verification is absent or inadequate on the 'lang' parameter used for file inclusion. An attacker without authentication could craft a malicious request to load local JavaScript files, potentially enabling remote code execution if they trick an administrator into clicking a malicious link. Version 7.2.4 provided a partial fix, while the vulnerability was completely resolved in version 7.2.5.
Based on public CVE data (MITRE/NVD).