Media File Manager [media-file-manager] < 1.4.3 (closed)
unknown
[en] The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI.
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.3
- Disclosed:
- Jan 31, 2019
CVE-2018-19040 on NVD →
Media File Manager [media-file-manager] < 1.4.3 (closed)
unknown
[en] The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI.
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.3
- Disclosed:
- Jan 31, 2019
CVE-2018-19041 on NVD →
Media File Manager [media-file-manager] < 1.4.3
unknown
[en] The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the dir_from and dir_to parameters of an mrelocator_move action to the wp-admin/admin-ajax.php URI.
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.3
- Disclosed:
- Jan 31, 2019
CVE-2018-19042 on NVD →
Media File Manager [media-file-manager] < 1.4.3 (closed)
unknown
[en] The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename) via a ../ directory traversal in the dir parameter of an mrelocator_rename action to the wp-admin/admin-ajax.php URI.
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.3
- Disclosed:
- Jan 31, 2019
CVE-2018-19043 on NVD →
Media File Manager [media-file-manager] < 1.4.3 (unfixed + closed)
unknown
Directory Traversal vulnerability found by boombyte in WordPress Media File Manager plugin (versions <= 1.4.2).
- Affected:
- up to 1.4.3
- Fix:
- No patched version reported
- Disclosed:
- Nov 13, 2018
Media File Manager [media-file-manager] < 1.4.3 (unfixed + closed)
unknown
Reflected Cross-Site Scripting (XSS) vulnerability found by boombyte in WordPress Media File Manager plugin (versions <= 1.4.2).
- Affected:
- up to 1.4.3
- Fix:
- No patched version reported
- Disclosed:
- Nov 13, 2018
Media File Manager <= 1.4.2 - Reflected Cross-Site Scripting
medium
The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI.
- CVSS:
- 6.1
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.3
- Disclosed:
- Nov 5, 2018
CVE-2018-19041 on NVD →
Media File Manager <= 1.4.2 - Directory Traversal to Arbitrary File Relocation
critical
The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the dir_from and dir_to parameters of an mrelocator_move action to the wp-admin/admin-ajax.php URI.
- CVSS:
- 9.8
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.3
- Disclosed:
- May 11, 2018
CVE-2018-19042 on NVD →
Media File Manager <= 1.4.2 - Directory Traversal to Directory Listing
medium
The Media File Manager plugin up to and including version 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI
- CVSS:
- 5.3
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.3
- Disclosed:
- May 11, 2018
CVE-2018-19040 on NVD →
Media File Manager <= 1.4.2 - Directory Traversal to Arbitrary File Read
medium
The Media File Manager plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1.4.2 via the dir parameter. This allows attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 5.3
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.3
- Disclosed:
- May 11, 2018
CVE-2018-19043 on NVD →
Media File Manager [media-file-manager] < 1.1.6 (closed)
unknown
Because of multiple vulnerabilities in this plugin, attackers can delete or update posts, creating, removing, listing directories, moving, renaming or deleting files, blind SQL injection and cross site scripting.
There is no fix at this moment.
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.6
- Disclosed:
- May 13, 2015
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database