cleantalk
Vulnerabilities and Security Researches

File Manager, 70d9f29b5770613904cf87693bbfa7607cf59e9a

Application

File Manager

Published on
Sep 17, 2018
Research Description
File Manager [wp-file-manager] < 3.1 File Manager <= 3.0 - Unauthenticated Arbitrary File Upload/Download The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to download arbitrary files from the server and upload arbitrary files that can be used for remote code execution.
Affected versions
max 3.1.
Status
vulnerable