PLUGIN SECURITY

Is File Manager safe?

file manager provides you ability to edit, delete, upload, download, copy and paste files and folders.

What this plugin does

  • Slug: wp-file-manager
  • Author: mndpsingh287
  • 1000000+ active installs
  • 92/100 rating (1488 reviews on wordpress.org)
  • 35209647 all-time downloads
  • On WordPress.org since 2016-08-09

elfinderfile managerftpwp file managerwp-filemanager

Maintenance status

  • Latest known version: 8.0.4
  • Last updated: 2026-04-21 12:53pm GMT
  • Tested up to WordPress: 6.9.7
  • Requires PHP: 5.2.4+

Known vulnerabilities

13 known CVEs on file for File Manager. Reported between 2018 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-6382 File Manager [wp-file-manager] < 8.0.4 Improper Control of Generation of Code ('Code Injection') Unknown < 8.0.4 8.0.4 2026-06-15 ✓ fixed in latest
CVE-2024-37254 File Manager [wp-file-manager] < 7.2.8 Missing Authorization Medium 4.3 < 7.2.8 7.2.8 2024-06-27 ✓ fixed in latest
CVE-2024-2654 File Manager [wp-file-manager] < 7.2.6 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 6.8 < 7.2.6 7.2.6 2024-04-03 ✓ fixed in latest
CVE-2024-1538 File Manager [wp-file-manager] < 7.2.5 Cross-Site Request Forgery (CSRF) High 8.8 < 7.2.5 7.2.5 2024-03-20 ✓ fixed in latest
CVE-2023-6825 File Manager [wp-file-manager] < 7.2.2 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Critical 9.9 < 7.2.2 7.2.2 2024-03-04 ✓ fixed in latest
CVE-2024-0761 File Manager [wp-file-manager] < 7.2.2 Use of Insufficiently Random Values High 7.5 < 7.2.2 7.2.2 2024-01-22 ✓ fixed in latest
CVE-2021-24177 File Manager [wp-file-manager] < 7.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 7.1 7.1 2021-02-26 ✓ fixed in latest
CVE-2020-25213 File Manager [wp-file-manager] < 6.9 Unrestricted Upload of File with Dangerous Type Critical 9.8 < 6.9 6.9 2020-09-01 ✓ fixed in latest
+ 9 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-24312 File Manager [wp-file-manager] < 6.5 Files or Directories Accessible to External Parties High 7.5 < 6.5 6.5 2020-08-13 ✓ fixed in latest
File Manager [wp-file-manager] < 4.9 Unknown < 4.9 4.9 2019-08-07 ✓ fixed in latest
CVE-2018-16967 File Manager [wp-file-manager] < 3.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.1 3.1 2018-09-17 ✓ fixed in latest
CVE-2018-16966, CVE-2018-16967 File Manager [wp-file-manager] < 3.1 Cross-Site Request Forgery (CSRF) High 8.8 < 3.1 3.1 2018-09-17 ✓ fixed in latest
CVE-2018-25105 File Manager [wp-file-manager] < 3.1 Missing Authorization Critical 9.8 < 3.1 3.1 2018-09-17 ✓ fixed in latest
CVE-2018-16363 File Manager [wp-file-manager] < 3.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.0 3.0 2018-09-06 ✓ fixed in latest
File Manager [wp-file-manager] < 5.2 Unknown < 5.2 5.2 ✓ fixed in latest
File Manager < 5.2 - Multiple Vulnerabilities Unknown < 5.2 5.2 ✓ fixed in latest
CVE-2024-0761 File Manager < 7.2.2 - Sensitive Information Exposure via Backup Filenames Unknown < 7.2.2 7.2.2 ✓ fixed in latest

How to fix it

Keep File Manager updated — 8.0.4 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.