CVE-2024-9669 is a Local JavaScript File Inclusion vulnerability affecting all versions up to and including 1.8.5 of the File Manager Pro – Filester plugin for WordPress. This high-severity vulnerability (CVSS 7.2) allows authenticated attackers with Administrator-level access to include and execute arbitrary files on the server, potentially leading to code execution, access control bypass, or sensitive data exposure. While a partial patch was released in version 1.8.5, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and no active exploitation or significant community discussion has been observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.6CPE matchmatch criteria | cpe:2.3:a:ninjateam:filester:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.