Filester
Vendor:
First CVE: Oct 16, 2023 · Active for 2 years
7
Total CVEs
More Total CVEs than 85% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 46% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Filester over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 16, 2023
2 years ago
Most Recent CVE
Dec 19, 2024
586 days ago
CVE Severity & Scoring
Filester7 CVEs
29%
71%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (71.4%)
Unknown0 (0.0%)
Required2 (28.6%)
Privileges Required
Low3 (42.9%)
High3 (42.9%)
None1 (14.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4827HIGH The File Manager Pro WordPress plugin before 1.8 does not properly check the CSRF nonce in the `fs_connector` AJAX action. This allows attackers to make highly privileged users per | Oct 16, 2023 | 8.8 | 29 | NO | NO |
CVE-2024-8066HIGH The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function in all versions up to, and incl | Nov 28, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-7031HIGH The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'njt_fs_saveSettingRestrictions' fu | Aug 3, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-9669HIGH The File Manager Pro – Filester plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 1.8.5 via the 'fm_locale' parameter. Thi | Nov 28, 2024 | 7.2 | 22 | NO | NO |
CVE-2023-4861HIGH The File Manager Pro WordPress plugin before 1.8.1 allows admin users to upload arbitrary files, even in environments where such a user should not be able to gain full control of t | Oct 16, 2023 | 7.2 | 22 | NO | NO |
CVE-2024-12331MEDIUM The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_install_plugin' function in a | Dec 19, 2024 | 4.3 | 15 | NO | NO |
CVE-2023-4862MEDIUM The File Manager Pro WordPress plugin before 1.8.1 does not adequately validate and escape some inputs, leading to XSS by high-privilege users. | Oct 16, 2023 | 4.8 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Filester
Top CWEs
Versions
No cataloged versions.