Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Filemanagerpro

First CVE: Sep 7, 2018Active for: 8 yearsTotal CVEs: 14
66.1
VTI Score
TOP TARGET

Filemanagerpro operates a focused file-management product whose vulnerability footprint skews toward serious outcomes, with an elevated share reaching critical severity and a strong tendency toward public exploit availability. The exposure recurs through structural weaknesses in file handling and web request processing—including unrestricted file uploads, cross-site request forgery, cross-site scripting, insecure file permissions, and code-injection flaws—that reflect the inherent risks of a web-facing utility handling untrusted input and file operations. Defenders should treat patches for this product as high-priority, particularly where it is exposed to untrusted users; live exploitation activity and severity figures are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
2.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
7.1%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Filemanagerpro over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 7, 2018
7 years ago
Most Recent CVE
Oct 16, 2024
646 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-25213CRITICAL
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder co
Sep 9, 20209.899YESYES
CVE-2020-24312HIGH
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated use
Aug 26, 20207.541NOYES
CVE-2024-1538HIGH
The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.4. This is due to missing or incorrect nonce validation
Mar 21, 20248.832NONO
CVE-2023-6846HIGH
The File Manager Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.3.4 via the mk_check_filemanager_php_syntax AJAX function.
Feb 5, 20248.832NONO
CVE-2018-25105CRITICAL
The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, and including, 3.0. This
Oct 16, 20249.830NONO
CVE-2018-16363MEDIUM
The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request because set_transient is used in file_fo
Sep 7, 20185.430NOYES
CVE-2018-16966HIGH
There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.
Apr 15, 20198.828NONO
CVE-2024-8746HIGH
The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing file type validation via the 'mk_file_folder_manager_shortcode
Oct 16, 20248.825NONO
CVE-2024-8507HIGH
The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.3.9. This is due to missing or incorrect nonce validat
Oct 16, 20248.825NONO
CVE-2024-0761HIGH
The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.1 due to insufficient randomness in the backup filen
Feb 5, 20247.523NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
36%
50%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (42.9%)
Unknown0 (0.0%)
Required8 (57.1%)
Privileges Required
Low4 (28.6%)
High1 (7.1%)
None9 (64.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
1 CVE
7.1% of CVEs· 100th percentile
Metasploit
1 CVE
7.1% of CVEs· 98th percentile
Nuclei
3 CVEs
21.4% of CVEs· 97th percentile
ExploitDB
1 CVE
7.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Filemanagerpro.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Filemanagerpro — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Filemanagerpro's Products

View all 3 CNAs →

Top CWEs