CVE · Medium

CVE-2024-2654 — File Manager [wp-file-manager] < 7.2.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-2654 File Manager [wp-file-manager] < 7.2.6 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 6.8 < 7.2.6 7.2.6 2024-04-03

CVE-2024-2654

The File Manager plugin for WordPress contains a directory traversal vulnerability in versions up to 7.2.5 affecting the fm_download_backup function. Administrators and higher-privileged users can exploit this flaw to access and read the contents of any zip file stored on the server. This vulnerability allows attackers with elevated privileges to potentially retrieve sensitive data contained within these archives. The issue is resolved in version 7.2.6 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.