CVE · High

CVE-2024-1538 — File Manager [wp-file-manager] < 7.2.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-1538 File Manager [wp-file-manager] < 7.2.5 Cross-Site Request Forgery (CSRF) High 8.8 < 7.2.5 7.2.5 2024-03-20

CVE-2024-1538

The File Manager plugin for WordPress versions prior to 7.2.5 contains a cross-site request forgery vulnerability affecting the wp_file_manager page, where nonce verification is absent or inadequate on the 'lang' parameter used for file inclusion. An attacker without authentication could craft a malicious request to load local JavaScript files, potentially enabling remote code execution if they trick an administrator into clicking a malicious link. Version 7.2.4 provided a partial fix, while the vulnerability was completely resolved in version 7.2.5.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.