CVE Database /
CVE-2024-2654
CVE · Medium
CVE-2024-2654 — File Manager [wp-file-manager] < 7.2.6
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-2654
|
File Manager [wp-file-manager] < 7.2.6 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
Medium
6.8
|
< 7.2.6
|
7.2.6 |
2024-04-03 |
—
|
CVE-2024-2654
The File Manager plugin for WordPress contains a directory traversal vulnerability in versions up to 7.2.5 affecting the fm_download_backup function. Administrators and higher-privileged users can exploit this flaw to access and read the contents of any zip file stored on the server. This vulnerability allows attackers with elevated privileges to potentially retrieve sensitive data contained within these archives. The issue is resolved in version 7.2.6 and later.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings