Extension WordPress
Vulnérabilités File Manager
Cette page rassemble les failles publiées pour File Manager, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de File Manager
13 fiches
File Manager <= 7.2.7 – Missing Authorization
The File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mk_file_manager_backup_callback function in versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with…
*-7.2.7
7.2.8
27/06/2024
File Manager <= 7.2.5 – Authenticated (Administrator+) Directory Traversal
The File Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.2.5 via the fm_download_backup function. This makes it possible for authenticated attackers, with administrator access and above, to read the…
*-7.2.5
7.2.6
03/04/2024
File Manager <= 7.2.4 – Cross-Site Request Forgery to Local JS File Inclusion
The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.4. This is due to missing or incorrect nonce validation on the wp_file_manager page that includes files through the…
*-7.2.4
7.2.5
20/03/2024
File Manager And File Manager Pro (Multiple Versions) – Directory Traversal
The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_file_folder_manager_action_callback_shortcode function. This…
*-7.2.1
7.2.2
04/03/2024
File Manager <= 7.2.1 – Sensitive Information Exposure via Backup Filenames
The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.1 due to insufficient randomness in the backup filenames, which use a timestamp plus 4 random digits. This makes…
*-7.2.1
7.2.2
22/01/2024
WP File Manager <= 7.0 – Reflected Cross-Site Scripting
In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint /wp-admin/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then reflected back on the…
[*, 7.1)
7.1
26/02/2021
File Manager <= 6.8 – Arbitrary File Upload/Remote Code Execution
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attackers…
*-6.8
6.9
01/09/2020
WP File Manager <= 6.4 – Unauthenticated Resource Access to Site Backups
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include…
*-6.4
6.5
13/08/2020
File Manager <= 4.8 – Missing Authorization on AJAX Actions
The File Manager plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various functions hooked via AJAX actions in versions up to, and including, 4.8. This makes it possible for authenticated attackers with…
*-4.8
4.9
07/08/2019
File Manager <= 3.0 – Unauthenticated Arbitrary File Upload/Download
The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to download arbitrary…
*-3.0
3.1
17/09/2018
File Manager <= 3.0 – Cross-Site Request Forgery
There is a CSRF vulnerability in the File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.
*-3.0
3.1
17/09/2018
File Manager <= 3.0 – Stored Cross-Site Scripting
There is an XSS vulnerability in the File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.
*-3.0
3.1
17/09/2018
File Manager <= 2.9 – Reflected Cross-Site Scripting
The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request because set_transient is used in file_folder_manager.php and there is an echo of lang in lib\wpfilemanager.php.
[*, 3.0)
3.0
06/09/2018
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.