File Manager
Vendor:
First CVE: Sep 7, 2018 · Active for 7 years
14
Total CVEs
More Total CVEs than 91% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
7.1%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact File Manager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 7, 2018
7 years ago
Most Recent CVE
Oct 16, 2024
646 days ago
CVE Severity & Scoring
File Manager14 CVEs
36%
50%
14%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (42.9%)
Unknown0 (0.0%)
Required8 (57.1%)
Privileges Required
Low4 (28.6%)
High1 (7.1%)
None9 (64.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25213CRITICAL The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder co | Sep 9, 2020 | 9.8 | 99 | YES | YES |
CVE-2020-24312HIGH mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated use | Aug 26, 2020 | 7.5 | 41 | NO | YES |
CVE-2024-1538HIGH The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.4. This is due to missing or incorrect nonce validation | Mar 21, 2024 | 8.8 | 32 | NO | NO |
CVE-2023-6846HIGH The File Manager Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.3.4 via the mk_check_filemanager_php_syntax AJAX function. | Feb 5, 2024 | 8.8 | 32 | NO | NO |
CVE-2018-25105CRITICAL The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, and including, 3.0. This | Oct 16, 2024 | 9.8 | 30 | NO | NO |
CVE-2018-16363MEDIUM The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request because set_transient is used in file_fo | Sep 7, 2018 | 5.4 | 30 | NO | YES |
CVE-2018-16966HIGH There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter. | Apr 15, 2019 | 8.8 | 28 | NO | NO |
CVE-2024-8746HIGH The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing file type validation via the 'mk_file_folder_manager_shortcode | Oct 16, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-8507HIGH The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.3.9. This is due to missing or incorrect nonce validat | Oct 16, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-0761HIGH The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.1 due to insufficient randomness in the backup filen | Feb 5, 2024 | 7.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
1 CVE
7.1% of CVEs· 97th percentile
Metasploit
1 CVE
7.1% of CVEs· 97th percentile
Nuclei
3 CVEs
21.4% of CVEs· 98th percentile
ExploitDB
1 CVE
7.1% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For File Manager
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.0 | 2 | 7.5 | 1.1% | 0 | 0 |
| 2.9 | 1 | 5.4 | 1.4% | 0 | 1 |