cleantalk
Vulnerabilities and Security Researches

File Manager, CVE-2018-25105

CVE, Research URL

CVE-2018-25105

Application

File Manager

Published on
Oct 16, 2024
Research Description
The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to download arbitrary files from the server and upload arbitrary files that can be used for remote code execution.
Affected versions
Min -, max 3.1.
Status
vulnerable