CVE · High

CVE-2024-7985 — FileOrganizer – WordPress File Manager [fileorganizer] < 1.1.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-7985 FileOrganizer – WordPress File Manager [fileorganizer] < 1.1.0 Unrestricted Upload of File with Dangerous Type High 8.8 < 1.1.0 1.1.0 2024-10-29

CVE-2024-7985

The FileOrganizer plugin for WordPress has a vulnerability that allows authenticated users with Subscriber-level access or higher to upload any type of file to the affected site's server. This is due to a lack of file type validation in the plugin's "fileorganizer_ajax_handler" function, which can potentially lead to remote code execution. To exploit this vulnerability, the FileOrganizer Pro plugin must be installed and active, and the user must have permissions granted by an administrator.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.