Showing 1 vulnerability on this page for secure_file_manager

Signals CISA KEV Ransomware Nuclei
themexa vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Secure-file-manager plugin through 2.5 for WordPress Remote Code Execution

vendor/elfinder/php/connector.minimal.php in the secure-file-manager plugin through 2.5 for WordPress loads elFinder code without proper access control. Thus, any authenticated user can run the elFinder upload command to achieve remote code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Dec 14, 2020
CVSS8.8v3.1EPSS18%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX