CVE-2020-25213 is a critical remote code execution vulnerability affecting the File Manager (wp-file-manager) plugin versions prior to 6.9 for WordPress. This flaw allows unauthenticated attackers to upload and execute arbitrary PHP code by exploiting a misconfigured example elFinder connector file. With a CVSS score of 9.8 (CRITICAL) and an EPSS score of 0.944, this vulnerability presents a severe risk, enabling full compromise of affected systems. It has been actively exploited in the wild since August 2020, with readily available exploit modules in Metasploit and Nuclei, and significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.9CPE matchmatch criteria | cpe:2.3:a:filemanagerpro:file_manager:*:*:*:*:free:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.