plugin

Media File Manager Vulnerabilities

11 known security issues reported for the Media File Manager WordPress plugin. Most recent disclosed Jan 31, 2019.

1 critical 3 medium

Running Media File Manager on your site? Check whether your installed version is affected.

Scan your site free

Media File Manager [media-file-manager] < 1.4.3 (closed)

unknown

[en] The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI.

Affected:
up to 1.4.3
Fixed in:
1.4.3
Disclosed:
Jan 31, 2019

CVE-2018-19040 on NVD →

Media File Manager [media-file-manager] < 1.4.3 (closed)

unknown

[en] The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI.

Affected:
up to 1.4.3
Fixed in:
1.4.3
Disclosed:
Jan 31, 2019

CVE-2018-19041 on NVD →

Media File Manager [media-file-manager] < 1.4.3

unknown

[en] The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the dir_from and dir_to parameters of an mrelocator_move action to the wp-admin/admin-ajax.php URI.

Affected:
up to 1.4.3
Fixed in:
1.4.3
Disclosed:
Jan 31, 2019

CVE-2018-19042 on NVD →

Media File Manager [media-file-manager] < 1.4.3 (closed)

unknown

[en] The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename) via a ../ directory traversal in the dir parameter of an mrelocator_rename action to the wp-admin/admin-ajax.php URI.

Affected:
up to 1.4.3
Fixed in:
1.4.3
Disclosed:
Jan 31, 2019

CVE-2018-19043 on NVD →

Media File Manager [media-file-manager] < 1.4.3 (unfixed + closed)

unknown

Directory Traversal vulnerability found by boombyte in WordPress Media File Manager plugin (versions <= 1.4.2).

Affected:
up to 1.4.3
Fix:
No patched version reported
Disclosed:
Nov 13, 2018

Media File Manager [media-file-manager] < 1.4.3 (unfixed + closed)

unknown

Reflected Cross-Site Scripting (XSS) vulnerability found by boombyte in WordPress Media File Manager plugin (versions <= 1.4.2).

Affected:
up to 1.4.3
Fix:
No patched version reported
Disclosed:
Nov 13, 2018

Media File Manager <= 1.4.2 - Reflected Cross-Site Scripting

medium

The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI.

CVSS:
6.1
Affected:
up to 1.4.2
Fixed in:
1.4.3
Disclosed:
Nov 5, 2018

CVE-2018-19041 on NVD →

Media File Manager <= 1.4.2 - Directory Traversal to Arbitrary File Relocation

critical

The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the dir_from and dir_to parameters of an mrelocator_move action to the wp-admin/admin-ajax.php URI.

CVSS:
9.8
Affected:
up to 1.4.2
Fixed in:
1.4.3
Disclosed:
May 11, 2018

CVE-2018-19042 on NVD →

Media File Manager <= 1.4.2 - Directory Traversal to Directory Listing

medium

The Media File Manager plugin up to and including version 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI

CVSS:
5.3
Affected:
up to 1.4.2
Fixed in:
1.4.3
Disclosed:
May 11, 2018

CVE-2018-19040 on NVD →

Media File Manager <= 1.4.2 - Directory Traversal to Arbitrary File Read

medium

The Media File Manager plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1.4.2 via the dir parameter. This allows attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS:
5.3
Affected:
up to 1.4.2
Fixed in:
1.4.3
Disclosed:
May 11, 2018

CVE-2018-19043 on NVD →

Media File Manager [media-file-manager] < 1.1.6 (closed)

unknown

Because of multiple vulnerabilities in this plugin, attackers can delete or update posts, creating, removing, listing directories, moving, renaming or deleting files, blind SQL injection and cross site scripting. There is no fix at this moment.

Affected:
up to 1.1.6
Fixed in:
1.1.6
Disclosed:
May 13, 2015

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database