Filemanagerpro

File Manager

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.41%
  • Veröffentlicht 16.10.2024 07:15:16
  • Zuletzt bearbeitet 17.10.2024 18:20:13

The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.3.9. This is due to missing or incorrect nonce validation on the 'mk_file_folder_manager' ajax action. This makes it possibl...

  • EPSS 3.27%
  • Veröffentlicht 16.10.2024 07:15:16
  • Zuletzt bearbeitet 17.10.2024 18:22:18

The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing file type validation via the 'mk_file_folder_manager_shortcode' ajax action in all versions up to, and including, 8.3.9. This makes ...

  • EPSS 0.83%
  • Veröffentlicht 16.10.2024 07:15:16
  • Zuletzt bearbeitet 17.10.2024 18:25:46

The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 8.3.9. This is due to a lack of proper checks on allowed file types. This makes it possible for unauthenticated attackers,...

  • EPSS 1.7%
  • Veröffentlicht 16.10.2024 07:15:05
  • Zuletzt bearbeitet 30.10.2024 18:23:57

The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to download arbitrary...

  • EPSS 1.86%
  • Veröffentlicht 09.04.2024 19:15:35
  • Zuletzt bearbeitet 29.09.2025 21:58:27

The File Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.2.5 via the fm_download_backup function. This makes it possible for authenticated attackers, with administrator access and above, to re...

  • EPSS 4.49%
  • Veröffentlicht 21.03.2024 04:15:09
  • Zuletzt bearbeitet 19.05.2025 13:47:57

The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.4. This is due to missing or incorrect nonce validation on the wp_file_manager page that includes files through the 'lang' par...

  • EPSS 0.44%
  • Veröffentlicht 05.02.2024 22:16:04
  • Zuletzt bearbeitet 24.03.2025 14:32:35

The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.1 due to insufficient randomness in the backup filenames, which use a timestamp plus 4 random digits. This makes it possib...

Exploit
  • EPSS 13.31%
  • Veröffentlicht 05.02.2024 22:15:56
  • Zuletzt bearbeitet 21.11.2024 08:44:40

The File Manager Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.3.4 via the mk_check_filemanager_php_syntax AJAX function. This makes it possible for authenticated attackers, with subscriber ac...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 05.04.2021 19:15:16
  • Zuletzt bearbeitet 24.03.2025 14:32:35

In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint /wp-admin/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then r...

Warnung Medienbericht Exploit
  • EPSS 94.4%
  • Veröffentlicht 09.09.2020 16:15:12
  • Zuletzt bearbeitet 07.11.2025 22:01:59

The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows att...