CVE Database /
CVE-2024-7985
CVE · High
CVE-2024-7985 — FileOrganizer – WordPress File Manager [fileorganizer] < 1.1.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-7985
|
FileOrganizer – WordPress File Manager [fileorganizer] < 1.1.0 |
Unrestricted Upload of File with Dangerous Type |
High
8.8
|
< 1.1.0
|
1.1.0 |
2024-10-29 |
—
|
CVE-2024-7985
The FileOrganizer plugin for WordPress has a vulnerability that allows authenticated users with Subscriber-level access or higher to upload any type of file to the affected site's server. This is due to a lack of file type validation in the plugin's "fileorganizer_ajax_handler" function, which can potentially lead to remote code execution. To exploit this vulnerability, the FileOrganizer Pro plugin must be installed and active, and the user must have permissions granted by an administrator.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings