plugin

Wp File Manager Pro Vulnerabilities

16 known security issues reported for the Wp File Manager Pro WordPress plugin. Most recent disclosed Aug 12, 2025.

1 critical 5 high 2 medium

Running Wp File Manager Pro on your site? Check whether your installed version is affected.

Scan your site free

Multiple elFinder Plugins <= (Various Versions) - Directory Traversal to Arbitrary File Deletion

medium

Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerability requires a site owner to explicitly make an instance of the file man...

CVSS:
6.5
Affected:
up to 8.4.2
Fixed in:
8.4.3
Disclosed:
Aug 12, 2025

CVE-2025-0818 on NVD →

File Manager Pro [wp-file-manager-pro] < 8.3.10

unknown

[en] The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing file type validation via the 'mk_file_folder_manager_shortcode' ajax action in all versions up to, and including, 8.3.9. This makes it possible for unauthenticated attackers, if granted access to t...

Affected:
up to 8.3.10
Fixed in:
8.3.10
Disclosed:
Oct 16, 2024

CVE-2024-8746 on NVD →

File Manager Pro [wp-file-manager-pro] < 8.3.10

unknown

[en] The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.3.9. This is due to missing or incorrect nonce validation on the 'mk_file_folder_manager' ajax action. This makes it possible for unauthenticated attackers to upload arbitrary files via a f...

Affected:
up to 8.3.10
Fixed in:
8.3.10
Disclosed:
Oct 16, 2024

CVE-2024-8507 on NVD →

File Manager Pro [wp-file-manager-pro] < 8.3.10

unknown

[en] The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 8.3.9. This is due to a lack of proper checks on allowed file types. This makes it possible for unauthenticated attackers, with permissions granted by an administrator, to upload .css and...

Affected:
up to 8.3.10
Fixed in:
8.3.10
Disclosed:
Oct 16, 2024

CVE-2024-8918 on NVD →

File Manager Pro <= 8.3.9 - Cross-Site Request Forgery to Arbitrary File Upload

high

The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.3.9. This is due to missing or incorrect nonce validation on the 'mk_file_folder_manager' ajax action. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged...

CVSS:
8.8
Affected:
up to 8.3.9
Fixed in:
8.3.10
Disclosed:
Oct 15, 2024

CVE-2024-8507 on NVD →

File Manager Pro <= 8.3.9 - Unauthenticated Backup File Download and Upload

high

The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing file type validation via the 'mk_file_folder_manager_shortcode' ajax action in all versions up to, and including, 8.3.9. This makes it possible for unauthenticated attackers, if granted access to the Fi...

CVSS:
7.5
Affected:
up to 8.3.9
Fixed in:
8.3.10
Disclosed:
Oct 15, 2024

CVE-2024-8746 on NVD →

File Manager Pro <= 8.3.9 - Unauthenticated Limited JavaScript File Upload

high

The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 8.3.9. This is due to a lack of proper checks on allowed file types. This makes it possible for unauthenticated attackers, with permissions granted by an administrator, to upload .css and .js...

CVSS:
7.4
Affected:
up to 8.3.9
Fixed in:
8.3.10
Disclosed:
Oct 15, 2024

CVE-2024-8918 on NVD →

File Manager Pro [wp-file-manager-pro] < 8.3.8

unknown

[en] The File Manager Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in the mk_file_folder_manager AJAX action in all versions up to, and including, 8.3.7. This makes it possible for authenticated attackers, with Subscriber-level access and abo...

Affected:
up to 8.3.8
Fixed in:
8.3.8
Disclosed:
Aug 23, 2024

CVE-2024-7559 on NVD →

File Manager Pro <= 8.3.7 - Authenticated (Subscriber+) Arbitrary File Upload

high

The File Manager Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in the mk_file_folder_manager AJAX action in all versions up to, and including, 8.3.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, t...

CVSS:
8.8
Affected:
up to 8.3.7
Fixed in:
8.3.8
Disclosed:
Aug 22, 2024

CVE-2024-7559 on NVD →

File Manager Pro [wp-file-manager-pro] < 8.3.5

unknown

[en] The File Manager Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tb' parameter in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

Affected:
up to 8.3.5
Fixed in:
8.3.5
Disclosed:
Mar 13, 2024

CVE-2023-7015 on NVD →

File Manager Pro [wp-file-manager-pro] < 8.3.5

unknown

[en] The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_file_folder_manager_action_callback_shortcode function. This makes it possible for attackers to...

Affected:
up to 8.3.5
Fixed in:
8.3.5
Disclosed:
Mar 13, 2024

CVE-2023-6825 on NVD →

File Manager And File Manager Pro (Multiple Versions) - Directory Traversal

critical

The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_file_folder_manager_action_callback_shortcode function. This makes it possible for attackers to read...

CVSS:
9.9
Affected:
up to 8.3.4
Fixed in:
8.3.5
Disclosed:
Mar 4, 2024

CVE-2023-6825 on NVD →

File Manager Pro <= 8.3.4 - Reflected Cross-Site Scripting

medium

The File Manager Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tb' parameter in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...

CVSS:
6.1
Affected:
up to 8.3.4
Fixed in:
8.3.5
Disclosed:
Feb 20, 2024

CVE-2023-7015 on NVD →

File Manager Pro [wp-file-manager-pro] < 8.3.5

unknown

[en] The File Manager Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.3.4 via the mk_check_filemanager_php_syntax AJAX function. This makes it possible for authenticated attackers, with subscriber access and above, to execute code on the server. Version 8.3.5 intr...

Affected:
up to 8.3.5
Fixed in:
8.3.5
Disclosed:
Feb 5, 2024

CVE-2023-6846 on NVD →

File Manager Pro <= 8.3.4 - Authenticated (Subscriber+) Arbitrary File Upload

high

The File Manager Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.3.4 via the mk_check_filemanager_php_syntax AJAX function. This makes it possible for authenticated attackers, with subscriber access and above, to execute code on the server. Version 8.3.5 introduce...

CVSS:
8.8
Affected:
up to 8.3.4
Fixed in:
8.3.5
Disclosed:
Jan 24, 2024

CVE-2023-6846 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database