PLUGIN SECURITY
Is Filester - File Manager Pro safe?
Best WordPress file manager without FTP access. Edit code with built-in editor, upload files, download plugins, download themes, manage wp directory, …
What this plugin does
- Slug:
filester - Author: Ninja Team
- 100000+ active installs
- 98/100 rating (152 reviews on wordpress.org)
- 1647452 all-time downloads
- On WordPress.org since 2020-05-15
Download Pluginfile managerftpwordpress file managerwp file manager
Maintenance status
- Last updated: 2026-08-23 10:04am GMT
- Tested up to WordPress: 7.1
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
9 known CVEs on file for Filester - File Manager Pro.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-6382 | File Manager Pro – Filester [filester] < 2.1.1 | Improper Control of Generation of Code ('Code Injection') | Unknown | < 2.1.1 | 2.1.1 | 2026-06-15 | — |
| CVE-2025-52710 | File Manager Pro – Filester [filester] < 1.8.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 1.8.9 | 1.8.9 | 2025-06-19 | — |
| CVE-2024-12331 | File Manager Pro – Filester [filester] < 1.8.7 | Missing Authorization | Medium 4.3 | < 1.8.7 | 1.8.7 | 2024-12-18 | — |
| CVE-2024-9669 | File Manager Pro – Filester [filester] < 1.8.6 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 7.2 | < 1.8.6 | 1.8.6 | 2024-11-27 | — |
| CVE-2024-8066 | File Manager Pro – Filester [filester] < 1.8.5 | Unrestricted Upload of File with Dangerous Type | High 8.8 | < 1.8.5 | 1.8.5 | 2024-11-27 | — |
| CVE-2024-7031 | File Manager Pro – Filester [filester] < 1.8.3 | Missing Authorization | High 8.8 | < 1.8.3 | 1.8.3 | 2024-08-02 | — |
| CVE-2023-4862 | File Manager Pro – Filester [filester] < 1.8.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 1.8.1 | 1.8.1 | 2023-09-19 | — |
| CVE-2023-4861 | File Manager Pro – Filester [filester] < 1.8.1 | Improper Control of Generation of Code ('Code Injection') | High 7.2 | < 1.8.1 | 1.8.1 | 2023-09-19 | — |
+ 3 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2023-4827 | File Manager Pro – Filester [filester] < 1.8 | Cross-Site Request Forgery (CSRF) | High 8.8 | < 1.8 | 1.8 | 2023-09-11 | — |
| — | File Manager Pro – Filester [filester] < 1.8.9 | Unrestricted Upload of File with Dangerous Type | High 7.2 | < 1.8.9 | 1.8.9 | 0000-00-00 | — |
| — | File Manager Pro – Filester [filester] < 1.9 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Medium 6.5 | < 1.9 | 1.9 | 0000-00-00 | — |
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- File Manager — 1000000+ active installs — 92/100 (1488)
- FileOrganizer – WordPress File Manager — 200000+ active installs — 96/100 (48) — max PHP 8.4
- FileBird – WordPress Media Library Folders & File Manager — 200000+ active installs — 94/100 (1121) — max PHP 8.4
- Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution — 100000+ active installs — 96/100 (438) — max PHP 8.4
- Real Media Library: Media Library Folder & File Manager — 100000+ active installs — 96/100 (290)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.