wordpress Vulnerabilities and Affected Products
Vulnerabilities associated with File Manager Plugin.
Products
Clear product- WordPress28 vulnerabilities
- wordpress-develop17 vulnerabilities
- adserve2 vulnerabilities
- Core2 vulnerabilities
- geo_controller2 vulnerabilities
- max_addons_pro_for_bricks2 vulnerabilities
- royal-elementor-addons2 vulnerabilities
- absolutely_glamorous_custom_admin1 vulnerability
- acf-on-the-go1 vulnerability
- BuddyBoss Theme1 vulnerability
- Buddypress1 vulnerability
- buddypress_cover1 vulnerability
- checkout_mestres1 vulnerability
- contact_form_drag_and_drop_form_builder1 vulnerability
- counter_box1 vulnerability
- cssigniter_elements_team1 vulnerability
- customer_reviews_for_woocommerce1 vulnerability
- directorist1 vulnerability
- easy_social_feed1 vulnerability
- elementsready_addons_for_elementor1 vulnerability
- elespare1 vulnerability
- email_customizer_for_woocommerce1 vulnerability
- enl_newsletter1 vulnerability
- external_database_based_actions1 vulnerability
- File Manager Plugin1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-25213CRITICAL | WordPress File Manager Plugin Remote Code Execution VulnerabilityThe File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to write PHP code into the wp-content/plugins/wp-file-manager/lib/files/ directory. This was exploited in the wild in August and September 2020. | CVSS10.0v3.1 | EPSS97.3% | PoCs14 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |