plugin

Wp Filemanager Vulnerabilities

5 known security issues reported for the Wp Filemanager WordPress plugin. Most recent disclosed May 15, 2013.

1 critical

Running Wp Filemanager on your site? Check whether your installed version is affected.

Scan your site free

wp-FileManager [wp-filemanager] < 1.1 (closed)

unknown

WP FileManager plugin's "path" parameter is prone to an arbitrary file download vulnerability. It allows an attacker to download arbitrary files within the context of the web server process. Update the plugin.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
May 15, 2013

wp-FileManager [wp-filemanager] < 1.1 (closed)

unknown

WP FileManager is prone to an arbitrary file download vulnerability. It allows an attacker to download arbitrary files within the context of the web server process. Update the plugin.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
May 14, 2013

wp-FileManager [wp-filemanager] < 1.3

unknown

[en] Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors.

Affected:
up to 1.3
Fixed in:
1.3
Disclosed:
Jan 10, 2008

CVE-2008-0222 on NVD →

Wp-FileManager <= 1.2 - Arbitrary File Upload

critical

Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors.

CVSS:
9.8
Affected:
up to 1.2
Fixed in:
1.3
Disclosed:
Jan 6, 2008

CVE-2008-0222 on NVD →

wp-FileManager [wp-filemanager] < 1.4.0 (closed)

unknown

The wp-filemanager WordPress plugin was affected by a File Download security vulnerability.

Affected:
up to 1.4.0
Fixed in:
1.4.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database