Secure File Manager < 2.8.2 - Remote Code Execution
highvendor/elfinder/php/connector.minimal.php in the secure-file-manager plugin through 2.5 for WordPress loads elFinder code without proper access control. Thus, any authenticated user can run the elFinder upload command to achieve remote code execution. NOTE: This vulnerability only affects products that are no longer su...
- CVSS:
- 8.8
- Affected:
- up to 2.8.2
- Fixed in:
- 2.8.2
- Disclosed:
- Nov 23, 2020