CVE-2025-0818
- EPSS 1.13%
- Veröffentlicht 13.08.2025 03:42:04
- Zuletzt bearbeitet 13.08.2025 17:33:46
Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerabilit...
CVE-2024-37254
- EPSS 0.15%
- Veröffentlicht 01.11.2024 15:15:22
- Zuletzt bearbeitet 01.11.2024 20:24:53
Missing Authorization vulnerability in mndpsingh287 File Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects File Manager: from n/a through 7.2.7.
CVE-2024-2654
- EPSS 1.86%
- Veröffentlicht 09.04.2024 19:15:35
- Zuletzt bearbeitet 29.09.2025 21:58:27
The File Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.2.5 via the fm_download_backup function. This makes it possible for authenticated attackers, with administrator access and above, to re...
CVE-2024-1538
- EPSS 4.49%
- Veröffentlicht 21.03.2024 04:15:09
- Zuletzt bearbeitet 19.05.2025 13:47:57
The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.4. This is due to missing or incorrect nonce validation on the wp_file_manager page that includes files through the 'lang' par...
CVE-2023-6825
- EPSS 3.75%
- Veröffentlicht 13.03.2024 16:15:08
- Zuletzt bearbeitet 21.01.2025 18:51:25
The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_file_folder_manager_action_cal...