Multiple Plugins <= Multiple Versions - Authenticated Remote Code Execution
high
Multiple plugins and/or themes for WordPress are vulnerable to Remote Code Execution in various versions. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.
- CVSS:
- 7.2
- Affected:
- up to 8.0.4
- Fixed in:
- 8.0.4
- Disclosed:
- Jun 15, 2026
CVE-2026-6382 on NVD →
File Manager [wp-file-manager] <= 23.2 (unfixed)
unknown
[en] Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in N-Media Frontend File Manager allows Code Injection.This issue affects Frontend File Manager: from n/a through 23.2.
- Affected:
- up to 23.2
- Fix:
- No patched version reported
- Disclosed:
- Jul 4, 2025
CVE-2025-27358 on NVD →
File Manager [wp-file-manager] < 7.2.8
unknown
[en] Missing Authorization vulnerability in mndpsingh287 File Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects File Manager: from n/a through 7.2.7.
- Affected:
- up to 7.2.8
- Fixed in:
- 7.2.8
- Disclosed:
- Nov 1, 2024
CVE-2024-37254 on NVD →
File Manager [wp-file-manager] < 3.1
unknown
[en] The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to download arbitrary files from the server and upload arbitrary files that can be use...
- Affected:
- up to 3.1
- Fixed in:
- 3.1
- Disclosed:
- Oct 16, 2024
CVE-2018-25105 on NVD →
File Manager <= 7.2.7 - Missing Authorization
medium
The File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mk_file_manager_backup_callback function in versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to trigger backu...
- CVSS:
- 4.3
- Affected:
- up to 7.2.7
- Fixed in:
- 7.2.8
- Disclosed:
- Jun 27, 2024
CVE-2024-37254 on NVD →
File Manager [wp-file-manager] < 7.2.6
unknown
[en] The File Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.2.5 via the fm_download_backup function. This makes it possible for authenticated attackers, with administrator access and above, to read the contents of arbitrary zip files on the server, which can c...
- Affected:
- up to 7.2.6
- Fixed in:
- 7.2.6
- Disclosed:
- Apr 9, 2024
CVE-2024-2654 on NVD →
File Manager <= 7.2.5 - Authenticated (Administrator+) Directory Traversal
medium
The File Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.2.5 via the fm_download_backup function. This makes it possible for authenticated attackers, with administrator access and above, to read the contents of arbitrary zip files on the server, which can contai...
- CVSS:
- 6.8
- Affected:
- up to 7.2.5
- Fixed in:
- 7.2.6
- Disclosed:
- Apr 3, 2024
CVE-2024-2654 on NVD →
File Manager [wp-file-manager] < 7.2.5
unknown
[en] The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.4. This is due to missing or incorrect nonce validation on the wp_file_manager page that includes files through the 'lang' parameter. This makes it possible for unauthenticated attackers to i...
- Affected:
- up to 7.2.5
- Fixed in:
- 7.2.5
- Disclosed:
- Mar 21, 2024
CVE-2024-1538 on NVD →
File Manager <= 7.2.4 - Cross-Site Request Forgery to Local JS File Inclusion
high
The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.4. This is due to missing or incorrect nonce validation on the wp_file_manager page that includes files through the 'lang' parameter. This makes it possible for unauthenticated attackers to includ...
- CVSS:
- 8.8
- Affected:
- up to 7.2.4
- Fixed in:
- 7.2.5
- Disclosed:
- Mar 20, 2024
CVE-2024-1538 on NVD →
File Manager [wp-file-manager] < 7.2.2
unknown
[en] The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_file_folder_manager_action_callback_shortcode function. This makes it possible for attackers to...
- Affected:
- up to 7.2.2
- Fixed in:
- 7.2.2
- Disclosed:
- Mar 13, 2024
CVE-2023-6825 on NVD →
File Manager And File Manager Pro (Multiple Versions) - Directory Traversal
critical
The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_file_folder_manager_action_callback_shortcode function. This makes it possible for attackers to read...
- CVSS:
- 9.9
- Affected:
- up to 7.2.1
- Fixed in:
- 7.2.2
- Disclosed:
- Mar 4, 2024
CVE-2023-6825 on NVD →
File Manager [wp-file-manager] < 7.2.2
unknown
[en] The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.1 due to insufficient randomness in the backup filenames, which use a timestamp plus 4 random digits. This makes it possible for unauthenticated attackers, to extract sensitive data inclu...
- Affected:
- up to 7.2.2
- Fixed in:
- 7.2.2
- Disclosed:
- Feb 5, 2024
CVE-2024-0761 on NVD →
File Manager <= 7.2.1 - Sensitive Information Exposure via Backup Filenames
high
The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.1 due to insufficient randomness in the backup filenames, which use a timestamp plus 4 random digits. This makes it possible for unauthenticated attackers, to extract sensitive data including...
- CVSS:
- 8.1
- Affected:
- up to 7.2.1
- Fixed in:
- 7.2.2
- Disclosed:
- Jan 22, 2024
CVE-2024-0761 on NVD →
File Manager [wp-file-manager] < 7.2.2
unknown
The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.1 due to insufficient randomness in the backup filenames, which use a timestamp plus 4 random digits. This makes it possible for unauthenticated attackers, to extract sensitive data including...
- Affected:
- up to 7.2.2
- Fixed in:
- 7.2.2
- Disclosed:
- Jan 22, 2024
File Manager [wp-file-manager] < 7.1
unknown
[en] In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint /wp-admin/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then reflected back on the web application response.
- Affected:
- up to 7.1
- Fixed in:
- 7.1
- Disclosed:
- Apr 5, 2021
CVE-2021-24177 on NVD →
WP File Manager <= 7.0 - Reflected Cross-Site Scripting
medium
In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint /wp-admin/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then reflected back on the web application response.
- CVSS:
- 5.4
- Affected:
- up to 7.1
- Fixed in:
- 7.1
- Disclosed:
- Feb 26, 2021
CVE-2021-24177 on NVD →
File Manager [wp-file-manager] < 6.9
unknown
[en] The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to...
- Affected:
- up to 6.9
- Fixed in:
- 6.9
- Disclosed:
- Sep 9, 2020
CVE-2020-25213 on NVD →
File Manager <= 6.8 - Arbitrary File Upload/Remote Code Execution
critical
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to write...
- CVSS:
- 9.8
- Affected:
- up to 6.8
- Fixed in:
- 6.9
- Disclosed:
- Sep 1, 2020
CVE-2020-25213 on NVD →
File Manager [wp-file-manager] < 6.5
unknown
[en] mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken.
- Affected:
- up to 6.5
- Fixed in:
- 6.5
- Disclosed:
- Aug 26, 2020
CVE-2020-24312 on NVD →
WP File Manager <= 6.4 - Unauthenticated Resource Access to Site Backups
high
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken.
- CVSS:
- 7.5
- Affected:
- up to 6.4
- Fixed in:
- 6.5
- Disclosed:
- Aug 13, 2020
CVE-2020-24312 on NVD →
File Manager <= 4.8 - Missing Authorization on AJAX Actions
medium
The File Manager plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various functions hooked via AJAX actions in versions up to, and including, 4.8. This makes it possible for authenticated attackers with subscriber-level permissions and above to delete back-ups and view sens...
- CVSS:
- 6.3
- Affected:
- up to 4.8
- Fixed in:
- 4.9
- Disclosed:
- Aug 7, 2019
File Manager [wp-file-manager] < 4.9
unknown
The File Manager plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various functions hooked via AJAX actions in versions up to, and including, 4.8. This makes it possible for authenticated attackers with subscriber-level permissions and above to delete back-ups and view sens...
- Affected:
- up to 4.9
- Fixed in:
- 4.9
- Disclosed:
- Aug 7, 2019
File Manager [wp-file-manager] < 3.1
unknown
[en] There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.
- Affected:
- up to 3.1
- Fixed in:
- 3.1
- Disclosed:
- Apr 15, 2019
CVE-2018-16966 on NVD →
File Manager [wp-file-manager] < 3.1
unknown
[en] There is an XSS vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.
- Affected:
- up to 3.1
- Fixed in:
- 3.1
- Disclosed:
- Apr 15, 2019
CVE-2018-16967 on NVD →
File Manager <= 3.0 - Unauthenticated Arbitrary File Upload/Download
critical
The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to download arbitrary files from the server and upload arbitrary files that can be used for...
- CVSS:
- 9.8
- Affected:
- up to 3.0
- Fixed in:
- 3.1
- Disclosed:
- Sep 17, 2018
CVE-2018-25105 on NVD →
File Manager <= 3.0 - Cross-Site Request Forgery
high
There is a CSRF vulnerability in the File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.
- CVSS:
- 8.8
- Affected:
- up to 3.0
- Fixed in:
- 3.1
- Disclosed:
- Sep 17, 2018
CVE-2018-16966 on NVD →
File Manager <= 3.0 - Stored Cross-Site Scripting
medium
There is an XSS vulnerability in the File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.
- CVSS:
- 6.1
- Affected:
- up to 3.0
- Fixed in:
- 3.1
- Disclosed:
- Sep 17, 2018
CVE-2018-16967 on NVD →
File Manager [wp-file-manager] < 3.1
unknown
The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to download arbitrary files from the server and upload arbitrary files that can be used for...
- Affected:
- up to 3.1
- Fixed in:
- 3.1
- Disclosed:
- Sep 17, 2018
File Manager [wp-file-manager] < 3.0
unknown
[en] The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request because set_transient is used in file_folder_manager.php and there is an echo of lang in lib\wpfilemanager.php.
- Affected:
- up to 3.0
- Fixed in:
- 3.0
- Disclosed:
- Sep 7, 2018
CVE-2018-16363 on NVD →
File Manager <= 2.9 - Reflected Cross-Site Scripting
medium
The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request because set_transient is used in file_folder_manager.php and there is an echo of lang in lib\wpfilemanager.php.
- CVSS:
- 6.1
- Affected:
- up to 3.0
- Fixed in:
- 3.0
- Disclosed:
- Sep 6, 2018
CVE-2018-16363 on NVD →
File Manager [wp-file-manager] < 5.2
unknown
Multiple vulnerabilities exist due to not checking the authentication of the user properly in the wp_ajax_* action calls. This results in SQL injection, backup download, backup deletion and backup restoration in the backup feature of the plugin. Authentication is required, but this can be of any user role.
Edit (WPS...
- Affected:
- up to 5.2
- Fixed in:
- 5.2
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database