cleantalk
Vulnerabilities and Security Researches

File Manager, 6f1a4455-051c-4f10-b0cb-e0d29e401c9e

Application

File Manager

Published on
-
Research Description
File Manager [wp-file-manager] < 5.2 File Manager &lt; 5.2 - Multiple Vulnerabilities Multiple vulnerabilities exist due to not checking the authentication of the user properly in the wp_ajax_* action calls. This results in SQL injection, backup download, backup deletion and backup restoration in the backup feature of the plugin. Authentication is required, but this can be of any user role. Edit (WPScanTeam): Original advisory reported fixed in 4.9, however the 4.9 was missing CSRF checks, which have been added in 5.1
Affected versions
max 5.2.
Status
vulnerable